Single Page Application
Fleetingsingle page application
Notes pointant ici
- OAuth 2.0 for Client-side Web Applications | Authorization | Google Developers SPA
- OAuth It s complicated
- playing with auth0 for the first time
- refresh token rotation
- Securing-SPAs-and-Blazor-Applications-using-the-BFF-Backend-for-Frontend-Pattern-Dominick-Baier
- using pkce does not prevent from using the client secret
- Which OAuth 2.0 Flow Should I Use?