%% You should probably cite draft-ietf-oauth-browser-based-apps instead of this I-D. @techreport{parecki-oauth-browser-based-apps-00, number = {draft-parecki-oauth-browser-based-apps-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-parecki-oauth-browser-based-apps/00/}, author = {Aaron Parecki and David Waite}, title = {{OAuth 2.0 for Browser-Based Apps}}, pagetotal = 10, year = 2018, month = nov, day = 5, abstract = {OAuth 2.0 authorization requests from apps running entirely in a browser are unable to use a Client Secret during the process, since they have no way to keep a secret confidential. This specification details the security considerations that must be taken into account when developing browser-based applications, as well as best practices for how they can securely implement OAuth 2.0.}, }