In scenarios where storing the client secret is not safe (e.g. desktop, mobile apps or JavaScript web apps running in the browser), you can use the authorization code with PKCE, as it provides protection against attacks where the authorization code may be intercepted. 引⽤元: https://developer.spotify.com/documentation/web-api/concepts/authorization 6
既に存在していた既存仕様やその拡張仕様を1つに集約したものです。 That also means specifically that this effort will not define any new behavior itself, it is just to capture behavior defined in other specs. 引⽤元: https://aaronparecki.com/2019/12/12/21/its-time-for-oauth-2-dot-1 17