Just in time for #iiw I published a blog post: "Is the OAuth 2.0 Implicit Flow Dead?" developer.okta.com/blog/2019…
1
8
16
Totally depends on your risk tolerance. Browsers are always a more risky environment, so that's something to keep in mind with refresh tokens.
If you are going to issue refresh tokens to JS, definitely rotate them after every use.
May 2, 2019 · 10:32 PM UTC
1
