This repository was archived by the owner on Aug 26, 2024. It is now read-only.
Optionally remove secret from get token request #153
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Microsoft identity platform's authentication flow for native & single page apps requires that the post request to get an access token has no client secret in it (See the client_secret description in the table of this section in the documentation).
For this reason, I have implemented an optional parameter for AuthorizationCodeGrant.handleAuthorizationResponse (and in turn, the _handleAuthorizationCode method aswell) to control whether the client secret should be included in this post request.
Contribution guidelines:
dart format
.Note that many Dart repos have a weekly cadence for reviewing PRs - please allow for some latency before initial review feedback.