Session 8: OAuth for Single Page Applications
Single Page Application run without a backend. All logic happens in the browser using JavaScript. To retrieve a token in order to call APIs certain measures should be taken. You will learn the best practice and we explore multiple ways SPAs can make use of OAuth.
- PKCE - Proof Key Code Exchange
- Code Flow with an SPA
- Depending on the SSO Session
- Assisted Token
- Using a Backend for Frontend
Related resources
Course Outline
1
Session 1: Introduction to OAuth
2
Session 2: OAuth vs OpenID Connect
3
Session 3: Tokens and APIs
4
Session 4: Server to Server Communication with OAuth
5
Session 5: Design tokens for your APIs
6
Session 6: Dynamic Clients and Metadata
7
Session 7: OAuth for Mobile Applications
8
Session 8: OAuth for Single Page Applications
Next steps
Ready to modernize IAM?
Start Today - Build security and improve ease of use to stay ahead of the competition.