ORwe need the attacker domain in the referer header in the last step so because of that here I use window.open to achieve thatReply·Article·Dec 24, 2024·OAuth Non-Happy Path to ATO