The Authorization Code Grant Type:
驗證并請求code
code 來了,state驗證這個請求就是我發(fā)的沒錯
type走得是authorization_code flow, code也是之前拿到的code,能把token拿來了嘛匀们?
如果不使用basic authentication那么帶上client id和client secret
Basic Authentication & OAuth:
得了走孽,確認無誤借尿,token發(fā)放
Implicit Grant Type
沒后端得spa用的驾锰,認證完畢token直接丟url里面給你自己拿
Too many security concerns
Client credential flow
The Resource Owner Password Credentials (ROPC) Grant Type
解決歷史問題庙曙,不用了
Refresh Token
client credential為什么不用蟋滴?不需要媳板,直接請求access token就行了
直接放入query string或hash fragment安全性不高桑腮,還是用form post
Error Types:
Dealing with Native apps
Proof Key for Code Exchange(PKCE)
Links the authorization request to the token request
Open ID connection
API-to-API Delegation
Token exchange