@aaronpk isn't the section you linked to just as much of a concern under the authorization code flow as the implicit flow? since javascript clients are public clients no matter what?
WeChat ID
aaronpk_tv
@aaronpk isn't the section you linked to just as much of a concern under the authorization code flow as the implicit flow? since javascript clients are public clients no matter what?
@aaronpk huh? But the redirect_uri is controlled by the same person who controls the code_challenge