More Single Page Application (SPA) and OAuth2 Thoughts
This post continues where “SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS” left off on the topic of securing Single Page Applications (SPAs). That post describes an architecture where the SPA running in the browser (User Agent)is acting as the…
Read article: More Single Page Application (SPA) and OAuth2 Thoughts








