5 min
Authorization Code and PKCE, by hand
Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.
- oauth2
- pkce
5 posts.
Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.
Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.
Integration tests against real PostgreSQL with Testcontainers, and RSA signing keys that survive a restart.
Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.
OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.