Hacker News new | ask | show | jobs
by rdegges 2979 days ago
Unfortunately, most SPA apps don't have a server side backed and thus cannot benefit from the additional security that the Authorization Code flow provides.
1 comments

They are in the same category as mobile apps in that respect, no? Both of them are "public clients" in terms of OAuth 2.0.