The keycloak javascript adapter - based on their documentation uses authorization code flow but with public client.
I just want to know if its offer the same security as authorization code flow with a private client?
Because, as i was discussing it with my colleagues, we realised something.
The implicit flow is not recommended as the access token will be part of the URL - might be stored in the browser history - but is it also not recommended because it will not be encrypted with the TLS/SSL?
In the authorization code flow of keycloak js adapter, keycloak will redirect to js application with authorization code as url parameter, if someone tried to intercept the call, they will be able to get the authorization code and easily exchange to a token as exchanging token won’t require client secret - is it possible to happen? Then for me, this is as good as implicit flow only, right? Or i might have missed something with keycloak’s documentation.
Also, in keycloak, there are 3 types of client - bearer, private and public - is this specific only to keycloak? Or included in oauth2 specifications?