I'm currently looking at the different OIDC flows and found AuthorizationCode flow and AuthorizationCode flow with PKCE.
Almost all places that I found said that the PKCE is a replacement for the Client secret and should be used by native applications.
Now i'm wondering what reason there is to not use a client secret and PKCE, would this be usefull or is this just not necessary?
I'm running an Openiddict server that i've tested will check for both the client secret and the code verifier. But everywhere i read, it just says PKCE and no (static) secret.