Tagged articles

PKCE

3 articles · Page 1 of 1
CodeNotes
CodeNotes
Aug 18, 2026 · Frontend Development

Mastering OAuth2 Login in the Frontend: Full Flowchart and Common Pitfalls

This article walks through the complete OAuth2 Authorization Code flow with PKCE for front‑end applications, explains each step with code examples, highlights six frequent pitfalls such as redirect_uri mismatches, missing state validation, PKCE requirements, one‑time code usage, URL leakage, and insecure token storage, and provides a ready‑to‑use implementation template.

Authorization CodeOAuth FlowOAuth2
0 likes · 11 min read
Mastering OAuth2 Login in the Frontend: Full Flowchart and Common Pitfalls
Xiaolin Talks Programming
Xiaolin Talks Programming
Aug 15, 2026 · Information Security

Enterprise API Security in Spring Boot: OAuth 2.1, mTLS & Signature Verification

This article details a comprehensive enterprise API security implementation using Spring Boot, covering OAuth 2.1 with PKCE and token exchange, mutual TLS for transport security, API signature verification to prevent tampering and replay, JWT encryption with JWE, fine-grained permission control, security auditing, gateway-level authentication, and alignment with OWASP API Top 10 vulnerabilities.

API SecurityJWEOAuth 2.1
0 likes · 19 min read
Enterprise API Security in Spring Boot: OAuth 2.1, mTLS & Signature Verification