PKCE
约 1 分钟阅读
- PKCE=Proof Key for Code Exchange
- 参考
- oauth.net/2/pkceLinkoauth.net/2/pkcePKCE=Proof Key for Code Exchange · 参考 · https://oauth.net/2/pkce/ · https://datatracker.ietf.org/doc/html/rfc7636 · Authorization Code Flow with Proof Key for Code Exchange笔记:PKCE
- RFC 7636RFCRFC 7636IETF Request for Comments standard document.RFC
- Authorization Code Flow with Proof Key for Code Exchange
- PKCE: What and Why?Linkdropbox.tech/developers/pkce--what-and-why-PKCE=Proof Key for Code Exchange · 参考 · https://oauth.net/2/pkce/ · https://datatracker.ietf.org/doc/html/rfc7636 · Authorization Code Flow with Proof Key for Code Exchange笔记:PKCE
- 基于 authorization code flow 用于替代 implicit flow - 避免回跳时附加 access_token
- 客户端请求添加 code_challenge, code_challenge_method
- code_challenge=base64(sha256(client_verifier))
- 可能 S256 加密
- code_challenge_method=plain,S256
- 此时构建 code_verifier 但不发送
- code_challenge=base64(sha256(client_verifier))
- 服务端响应 authorization_code
- 客户端请求 token 接口 - code={authorization_code},code_verifier,grant_type=authorization_code
- 服务端检查 基于初始请求的 code_challenge 检查 code_verifier
- 通过检查响应 access_token
- 客户端请求添加 code_challenge, code_challenge_method
关联信息
反向链接、本文链接的其他页面和外部资料。
References
标准文档1 条
- RFC 7636datatracker.ietf.org/doc/html/rfc7636RFC
IETF Request for Comments standard document.
其他外链3 条
- auth0.com/docs/authorization/flows/authorization-code-flow-with-proof-key-for-code-exchange-pkceauth0.com/docs/authorization/flows/authorization-code-flow-with-proof-key-for-code-exchange-pkce
- dropbox.tech/developers/pkce--what-and-why-dropbox.tech/developers/pkce--what-and-why-
- oauth.net/2/pkceoauth.net/2/pkce