docs: light refactor

This commit is contained in:
joel@joellee.org committed 2023-04-09 13:11:24 +08:00
1 parent 2ac090e054
commit 1278fa2e84
1 file changed
+4 -4
@@ -71,7 +71,7 @@ It introduces a few additional steps which guard a against replay and URL captur
>
<div className="border-b pb-3">
<Accordion.Item
header={<span className="text-scale-1200">Implicit</span>}
header={<span className="text-scale-1200 font-bold">Implicit</span>}
id={`ssr-implicit-flow`}
>
@@ -103,17 +103,17 @@ approach also avoids leaking credentials in request or access logs. If you wish
</div>
<div className="border-b pb-3">
<Accordion.Item
header={<span className="text-scale-1200">PKCE</span>}
header={<span className="text-scale-1200 font-bold">PKCE</span>}
id={`ssr-pkce-flow`}
>
When using the PKCE flow, a redirect URL will be returned with the following structure:
```
https://yourapp.com/...?code=<...>
```
The `code` parameter is commonly known as the Auth Code. The Auth Code can then be exchanged for an access token by calling `exchangeCodeForSession(code)` method.
The `code` parameter is commonly known as the Auth Code and can be exchanged for an access token by calling `exchangeCodeForSession(code)`.
<Admonition type="info">
For security purposes, the code has a validity of 5 minutes and can only be exchanged for an access token once. You
will need to initiate the authentication flow again if you wish to obtain a new access token.
will need to restart the authentication flow from scratch if you wish to obtain a new access token.
</Admonition>
As the flow is run server side, `localStorage` may not be available. You may configure the client library to use a custom storage adapter an alternate backing storage such as cookies