Open
Description
There seems to be some progress in general opinion about implicit grant flow best practices, where probably we should require https://www.oauth.com/oauth2-servers/pkce/ in how the remoteStorage spec uses OAuth Implicit Grant.
https://tools.ietf.org/id/draft-parecki-oauth-browser-based-apps-02.txt
https://medium.com/oauth-2/why-you-should-stop-using-the-oauth-implicit-grant-2436ced1c926
https://www.google.com/search?q=implicit+flow+problems
Metadata
Assignees
Labels
No labels