Hacker News new | past | comments | ask | show | jobs | submit login

"Through I'm not sure if requiring (instead of just allowing) PKCE is strictly OIDC compliant"

It's technically not compliant, but people definitely do so, and there are definite security advantages to requiring it.

Technically the 'nonce' in OpenID Connect provides the same protections, and hence the OAuth Security BCP says (in a lot more words) that you may omit PKCE when using OIDC. However in practice, based on a period in the trenches that I've mostly repressed now, the way the mechanisms were designed means clients are far more likely to use PKCE correctly than to use nonce correctly.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: