From 5a87c8a932071246d3e4ba3733563bcf018abc93 Mon Sep 17 00:00:00 2001 From: Andrew Korshunov Date: Tue, 20 Oct 2020 23:48:44 +0300 Subject: [PATCH] fix(auth): Allow PKCE for legacy AccessCode OAuth2 Grant Type (#6011) fixes #6010 Co-authored-by: Andrew Korshunov --- src/core/oauth2-authorize.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/core/oauth2-authorize.js b/src/core/oauth2-authorize.js index 858be707..15f2054f 100644 --- a/src/core/oauth2-authorize.js +++ b/src/core/oauth2-authorize.js @@ -74,7 +74,7 @@ export default function authorize ( { auth, authActions, errActions, configs, au query.push("realm=" + encodeURIComponent(authConfigs.realm)) } - if (flow === "authorizationCode" && authConfigs.usePkceWithAuthorizationCodeGrant) { + if ((flow === "authorizationCode" || flow === "accessCode") && authConfigs.usePkceWithAuthorizationCodeGrant) { const codeVerifier = generateCodeVerifier() const codeChallenge = createCodeChallenge(codeVerifier)