Skip to content

Conversation

@eikemeier
Copy link

OAuth 2.0 security best current practice draft recommends using PKCE: https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-22.html#section-2.1.1-2.2.1

There is a feature request to integrate PKCE into golang.org/x/oauth2, but currently no native support.

@ewanharris
Copy link
Contributor

Thanks for the PR @eikemeier, let me discuss with the team how we'd like to approach this (we tend to try and keep the samples aligned with their quickstart) and get back to you.

OAuth 2.0 security best current practice draft recommends using PKCE:
https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-22.html#section-2.1.1-2.2.1

Signed-off-by: Oliver Eikemeier <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants