SIGN IN SIGN UP

oauth: reserve the security log for apparent attacks

Every rejection the authorize endpoint made was logged as a security
event, so a client that forgot response_type or repeated a parameter left
the same kind of record as one probing for an unregistered redirect_uri,
and the log filled up with other clients' bugs.

JIRA-Ref: CMK-38012
Change-Id: I31f4c75da7aeed64f1d52ce415b5c2bb5e840fc4
M
Max Linke committed
4eb218efde7a3847abd2a5800eb47e25090b6c90
Parent: ff815b2
Committed by Jenkins <jenkins@review.lan.tribe29.com> on 8/21/2026, 2:02:34 PM