OAuth Sketch Notes Q&A - PKCE, Scopes, Security, Passwordless
Fleeting- External reference:
a cookie to deal with session create fewer attack surface
It is discussed the trichotomy between authentication vs identification vs authorization.
reference token vs self-encoded access token