4 ms·
Implicit grants are more dangerous for two reasons: (1) the process wherein the token is sent to the client can have serious security implications (especially f
by dperfect 10y ago
Implicit grants are more dangerous for two reasons: (1) the process wherein the token is sent to the client can have serious security implications (especially for web apps) and (2) if your app communicates with any app-specific back end, the transfer of auth tokens between the app and back end is an additional temptation that is prone to have even more security issues.
I do agree - if you have an app that is 100% client-side, and you're either using an official SDK or know what you're doing, implicit grants can be done securely (just as secure as any other bearer or session token, as you mention). The problem is that many app developers choose the implicit flow initially (because it's easier to implement), but then end up using it in ways that would be much better suited to the authorization grant flow.