Authorization Code Grant: is it safe to send the tokens to the client?

前端 未结 0 1198
时光说笑
时光说笑 2021-02-20 11:41

Let\'s say I have a SPA with a back-end on the same domain. If I had to connect to an external OAuth provider (let\'s say Google), the Authorization Code Flow (without PKCE) is

相关标签:
回答
  • 消灭零回复
提交回复
热议问题