Dear Group,
I am trying to use ZAP to scan a website (eg.
https://test.com), but if I want to enter or browse the target website (
https://test.com), I have to authenticate, and the target website is using Oauth, so I have to authenticate it in another website (e.g.
https://auth.com) with unique nonce and state in every request.
So when I use spider scan to scan the target URL (
https://test.com) , I can only get several results since I didn't authenticate to access the website, can ZAP handle this type of situation?
Thanks in advance for your help
