Brock 1/3/2019

The State of the Implicit Flow in OAuth2

Read Original

This technical article examines the security history and current status of the OAuth2 implicit flow, prompted by new IETF drafts. It discusses the flow's design for SPAs, inherent risks like token exposure in URLs, and the community's shift towards more secure alternatives like the authorization code flow with PKCE.

The State of the Implicit Flow in OAuth2

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week