I don't understand why you would use PKCE for an oauth when you could alternately store a key and have it be returned in the state. Is this like jwt and the idea is it's doing some weird crypto so you can fire off oauth from one server and have the request returned to something else in your load balancer and your own servers don't have to coordinate?

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/mcc/statuses/115228172116685323 on your instance and quote it. (Note that quoting is not supported in Mastodon.)