OAuth 2.1 draft is out
+ PKCE for authz code grant
+ Exact matching for redirect URIs
- Implicit & Resource Owner Password Creds grants
- Bearer tokens in query params
+ Refresh tokens: sender-constrained or one-time use
@aaronpk, @tlodderstedt, @DickHardt
https://tools.ietf.org/html/draft-parecki-oauth-v2-1-01
+ PKCE for authz code grant
+ Exact matching for redirect URIs
- Implicit & Resource Owner Password Creds grants
- Bearer tokens in query params
+ Refresh tokens: sender-constrained or one-time use
@aaronpk, @tlodderstedt, @DickHardt
https://tools.ietf.org/html/draft-parecki-oauth-v2-1-01