Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6091151
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T12:17:41+00:00 2026-05-23T12:17:41+00:00

My question is pretty simple: If you have two web-application components: Server-side (secret-capable) code

  • 0

My question is pretty simple:

If you have two web-application components:

  1. Server-side (secret-capable) code in PHP, Python, Perl … whatever
  2. The javascript output and interpreted by the browser

Given a single redirection to the authorisation endpoint (and back) is it possible to specify and transfer the information for:

  1. An authorization code grant (for the server-side code)
  2. An implicit grant with restricted rights for the Javascript

thereby transferring the two grants (one in the request-url proper and the other in the fragment) in one round-trip without violating the RFC?

One redirect-loop seems cleaner than one for each grant (even if the second doesn’t block due to previous authorization)

Thanks in advance!

References

  1. https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-16#section-4.2

edit 1: code_and_token seems to be the type of thing I am after … an auth code grant for the server to request the access code using its credentials … and an implicit token for the javascript. As mov matake mentions, it was pulled from the RFC after v11, with no real note as to why. Facebook and Google seem to support this which makes me suspect it will return.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T12:17:41+00:00Added an answer on May 23, 2026 at 12:17 pm

    The token_and_code request type was removed from the specification because it needed significant work in terms of security analysis and rules, and no one offered to do it. It was originally proposed by a Twitter engineer who left the working group shortly after.

    It will not be added to the specification, but it can easily be introduced by an extension. Google supported this flow on the list, but later said they will not implement it, and instead, will implement something else using HTML5 features.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Pretty simple question this time around. I have an application that communicates with another
I have a pretty simple question. If I'm comparing two parameters in a JSP
Pretty simple question: When i have a persistable object, it usually has a property
I am working on a pretty simple web application (famous last words) and am
The question is pretty simple actually. I have a module in my system containing
I have a pretty simple question (and these are typically the ones I spend
OK. So I have a pretty simple question: I want to be able to
I have a web-application written on ASP.NET MVC 3. On client side I used
I have what I think is a pretty simple question. I have a report
Pretty simple question, I'm writing an XML document and i'm not sure how to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.