Skip to content

OAuth 2.1 Support/Roadmap #9356

Closed
Closed
@metacubed

Description

@metacubed

Which features from OAuth 2.1 will be supported by Spring Security? Is there a roadmap or any documentation on this topic?

For example:

  • PKCE support (partially implemented)
  • Remove implicit grant (deprecated, to be removed)
  • Remove password grant
  • Remove query-based bearer tokens
  • Constraints on refresh tokens
  • Redirect URI enforcement changes

Metadata

Metadata

Assignees

Labels

in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions