Azure-docs: IETF recommends using Auth Code + PKCE for SPAs with no backend

Created on 18 Mar 2020  Â·  3Comments  Â·  Source: MicrosoftDocs/azure-docs

The IETF has recommended using Auth Code + PKCE over Implicit flow for several years for SPAs. Could you please recommend reviewing this important document to ensure current practice is employed for new applications.

This is summarised in section 4.

"However, there are several drawbacks to the implicit flow, generally involving vulnerabilities associated with the exposure of the access token in the URL. See Section 9.8 for an analysis of these attacks and the drawbacks of using the implicit flow in browsers. Additional attacks and security considerations can be found in [oauth-security-topics]."

https://tools.ietf.org/html/draft-ietf-oauth-browser-based-apps-05


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri1 active-directorsvc cxp develosubsvc product-question triaged

Most helpful comment

We will be updating this documentation soon with the general availability of Auth Code + PKCE for MSAL.js coming in the next month or so

All 3 comments

@paulspencerwilliams Thank you for the feedback. We are actively investigating and will get back to you soon.

We will be updating this documentation soon with the general availability of Auth Code + PKCE for MSAL.js coming in the next month or so

@paulspencerwilliams We would be closing this thread now. Let us know if you need further help on the same.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

DeepPuddles picture DeepPuddles  Â·  3Comments

jebeld17 picture jebeld17  Â·  3Comments

JamesDLD picture JamesDLD  Â·  3Comments

paulmarshall picture paulmarshall  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments