%% You should probably cite draft-ietf-oauth-browser-based-apps-17 instead of this revision. @techreport{ietf-oauth-browser-based-apps-00, number = {draft-ietf-oauth-browser-based-apps-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-browser-based-apps/00/}, author = {Aaron Parecki and David Waite}, title = {{OAuth 2.0 for Browser-Based Apps}}, pagetotal = 14, year = , month = , day = , abstract = {OAuth 2.0 authorization requests from apps running entirely in a browser are unable to use a Client Secret during the process, since they have no way to keep a secret confidential. This specification details the security considerations that must be taken into account when developing browser-based applications, as well as best practices for how they can securely implement OAuth 2.0.}, }