-
Notifications
You must be signed in to change notification settings - Fork 6.2k
Closed
Labels
in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
Description
Which features from OAuth 2.1 will be supported by Spring Security? Is there a roadmap or any documentation on this topic?
For example:
- PKCE support (partially implemented)
- Remove implicit grant (deprecated, to be removed)
- Remove password grant
- Remove query-based bearer tokens
- Constraints on refresh tokens
- Redirect URI enforcement changes
Metadata
Metadata
Assignees
Labels
in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)