So login by Apple seems to be #OpenID Connect with some twist. A huge win for #oidc
4
17
40
lack of code replay protection and proprietary client authentication method?
3
3
In my testing, I wasn't able to use an authorization code twice. Did you see something different?

Jun 9, 2019 · 3:29 AM UTC

2
Replying to @aaronpk @_nat_en
yes I meant code injection == code replay in the authz response
1