4 ms·
FWIW, the language on your PKCE flow is wrong: * It's not establishment of a "session", but a token set which you're issuing. * The authorization server will
by krooj 3y ago
FWIW, the language on your PKCE flow is wrong:
* It's not establishment of a "session", but a token set which you're issuing.
* The authorization server will return those tokens after validating the code_verifier.
Also, be careful about PKCE on mobile platforms. Unless you're specifically mapping or restricting redirect_uris to an Android intent, on that platform, you're subject to replay attacks due to some cookie sharing in Chrome.
- aceofspade 3y agoSupabase Auth Engineer here. You are right that a token set is issued and that the authorization server will return an access_token and a refresh_token after validating the code_verifier we chose the term "session" instead of token set as a token (loosely speaking) maps to a server session and we felt that might be easier to understand for our readers who are coming in without an auth background. Sorry for any confusion caused that might have caused. Thanks for the heads up about replay attacks - we'll be sure to let the Kotlin/Java library developers know about the potential vulnerabilities that you've mentioned.