4 ms·
I wonder if the same recommendation (use Authorization Code Grant flow plus PKCE instead of Implicit Grant) should be made for SPA (single page applications), t
by idubrov 8y ago
I wonder if the same recommendation (use Authorization Code Grant flow plus PKCE instead of Implicit Grant) should be made for SPA (single page applications), too.
- rdegges 8y agoUnfortunately, most SPA apps don't have a server side backed and thus cannot benefit from the additional security that the Authorization Code flow provides.
- idubrov 8y agoThey are in the same category as mobile apps in that respect, no? Both of them are "public clients" in terms of OAuth 2.0.