You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
The current definition of OAuth 2.1 expects a client secret when a confidential app is used in combination with PKCE.
Describe the solution you'd like
Check of client secret if PKCE flow is used when app is typed as confidential.
Describe alternatives you've considered
Split of compliance with a different version, to bet at least different from the new version of OAuth.
Is your feature request related to a problem? Please describe.
The current definition of OAuth 2.1 expects a client secret when a confidential app is used in combination with PKCE.
Describe the solution you'd like
Check of client secret if PKCE flow is used when app is typed as confidential.
Describe alternatives you've considered
Split of compliance with a different version, to bet at least different from the new version of OAuth.
Additional context
https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-09#authorization_codes
The text was updated successfully, but these errors were encountered: