3 ms·
It even says so on the official website ( https://oauth.net/2/grant-types/implicit/ https://oauth.net/2/grant-types/implicit/ ) - astonishing that they can't ge
by adumbledore 8y ago
It even says so on the official website ( https://oauth.net/2/grant-types/implicit/ https://oauth.net/2/grant-types/implicit/ ) - astonishing that they can't get this right. Maybe says something about the product?
- UncleMeat 8y agoYep. I'm fairly concerned about an identity management company publishing this information.
- caseysoftware 8y agoAuthor here - Entirely agree and we recommend using Auth Code+PKCE whenever possible. This post is intended to be the first of a few starting with the base spec. In the next one, I plan to go over the RFCs for JWT, Revocation, Inspection, PKCE, the AppAuth pattern, and probably a few others. Thanks for the note though.
- rahulrav 8y agoThanks for the shoutout to AppAuth (https://appauth.io https://appauth.io). It’s our 20% project at Google.