1. Reusing Authorization Token ⇒ /code=<code here>

2. Redirect_uri not being Validated

3. State Parameter - CSRF Anti token