OAuth 2.0 PKCE transition: Enforcing S256 challenge methods for public clients
Transitioning from static secrets to PKCE Public clients in OAuth 2.0 are moving away from the use of client_secret due to the inability to securely store credentials in client-side applications. The implementation of Proof Key for Code Exchange (PKCE) as defined in RFC 7636 addresses this by introducing a code_verifier and code_challenge to bind the authori