aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
10 stars 8 forks source link

Appendix A.2 #43

Closed mattjm closed 5 months ago

mattjm commented 9 months ago

On the last bullet point in A.2:

I was under the impression the browser returns control to the client with the authorization code, and then the client uses the authorization code with the /token endpoint directly.

aaronpk commented 9 months ago

Yes you're correct, this is worded poorly