You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Enhancements
Support public OAuth2 clients that hold no client secret (#178).
OAuth2ClientConfiguration gains init(publicClientIdentifier:environment:guestUsername:guestPassword:) and a read-only isPublicClient flag. A public client identifies itself with client_id in the token grant body and sends no Authorization: Basic header across every grant type. Confidential clients are unchanged.
Client-level authorization for a public client through OAuth2RequestPipelineMiddleware requires guest credentials. Client-level basic, and client-level bearer without guest credentials, fail with OAuth2Error.internalFailure instead of sending a request with no credential.
A public client using authorization_code must use PKCE and the authorization server must enforce it (RFC 8252 §6). Pass code_challenge via OAuth2AuthorizationRequest.additionalParameters and code_verifier via tokenGrantRequestAdditionalBodyParameters.