Account hijacking using “dirty dancing” in sign-in OAuth-flows