aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
10 stars 8 forks source link

Describe why not to return access token directly #32

Closed PieterKas closed 10 months ago

PieterKas commented 12 months ago

It was suggested that instead of an authorization code, the service returns an access token directly. Add security considerations to outline why this is not an appropriate pattern for this protocol.