I was wondering what the primary reason was for using a hidden iframe with prompt=none when silently refreshing the tokens in OpenID Connect? As the spec [1] says that the /authorize endpoint must support POST could this not be done via an XHR request?
[1] https://openid.net/specs/openid-connect-core-1_0.html#AuthorizationEndpoint (3.1.2.1. Authentication Request)