Skip to main content
CodeOath
← All posts

Auth & Security63 min total · 19 parts

OAuth 2.0 and JWT Explained: What Really Happens When You Click "Sign In"

Part 5 of 19 · ~2 min

Why the Authorization Code Flow Is Secure by Design

The reason this holds up is almost entirely down to where step 5 physically happens. Nobody watching Priya's browser — not an extension, not a script running on some other tab, not anyone with access to her router — gets a look at that request, because it never routes through her machine at all. It's Tasklight's server dialing Kestrel's server directly. Which means the access token itself, the credential that actually opens doors at Kestrel's and Tasklight's APIs, is never sitting in a URL, never lands in a browser history entry, never shows up in an access log anywhere Priya's browser touched.

Compare that to the authorization code, which does pass through Priya's browser in step 4 — and notice how little that code is actually worth by itself. Kestrel gives it a lifespan measured in seconds, not minutes. The moment it's redeemed once, Kestrel marks it dead, and a second attempt to redeem it is treated as suspicious rather than simply rejected. And redeeming it at all requires pairing it with tasklight-web's client_secret, a value that has never once existed anywhere near Priya's browser. Picture the worst case — someone's sniffing an open coffee-shop network, or a referrer header leaks the code to a page it shouldn't have gone to — and they're still holding half of what they'd need. The other half never left Tasklight's server.

Put those two facts together and you get the reason this whole flow assumes what's called a confidential client: a client with somewhere private to keep that secret. Tasklight's web app has exactly that — a backend nobody but Tasklight's own infrastructure can reach. The CLI doesn't, and neither does the embeddable widget, because both of them ship code to a place someone else controls, and anything sitting in code that ships to someone else's machine can be extracted by whoever's determined enough to try. A client_secret stashed in either one wouldn't be secret for long. Which is precisely the problem the next chapter has to solve.