data:image/s3,"s3://crabby-images/ebfcd/ebfcd54a2ee7f6bb8423b7f235946767e027c0be" alt=""
An OAuth Client exchanges that code for a Refresh Token (Green 'Rt'), using its client secret (red 'Cs') on the request.
The OAuth Client can exchange the refresh token for Access Token (green 'At'), also using its client secret on the request.
The Access Token is then presented by the Client to the REST endpoint (yellow 'API') , as proof that the User has previously made the grant (ie gave their consent).
For native clients, it's unrealistic to expect that the app could be distributed (through an app store) with a secret (such as 'Cs') so instead the app can be distributed with a global Application Secret (red 'As'), this subsequently exchanged for a unique Cs (as in the dynamic registration spec).
No comments:
Post a Comment