| ▲ | oasisbob 7 hours ago | |
The service wouldn't have access to the refresh token? How does authentication with the client-secret-holding intermediary work? It's easy to see how this would work with sufficiently sophisticated clients in some use-cases, say via a vault plugin, but posing this as a universal necessity feels like a big departure from typical oauth flows, and the added complexity could be harmful depending on what home-grown solutions are used to implement it. | ||