Update OAuth2-Front-Approach.md

This commit is contained in:
Ste Vaidis 2024-12-15 18:54:42 +02:00
parent e31241c951
commit 41c6d29936

View File

@ -136,10 +136,10 @@ Content-Type: application/json
#### 2.2 Backend #### 2.2 Backend
1. The backend **receives** the authorization `code` form frontend (Frontend POST at `xorismesiti.gr/api/auth/exchange-token`) 1. The backend **receives** the authorization `code` form the frontend POST at `xorismesiti.gr/api/auth/exchange-token`
2. The backend **POST** Authorization `code` to Google API 2. The backend **POST** Authorization `code` to Google API
3. The Google API respond to backend POST with the tokens `access_token` and `refresh_token` 3. The Google API respond to backend POST with the tokens `access_token` and `refresh_token`
4. The backend **respond** to frontend with the tokens (respond to frontend POST at `xorismesiti.gr/api/auth/exchange-token`) 4. The backend **response** to frontends POST with the the tokens
*Security: The backend never expose the client_secret to the frontend. This step should always be handled on the backend.* *Security: The backend never expose the client_secret to the frontend. This step should always be handled on the backend.*