Similar to How to handle OAuth flow with Doorkeeper in API Mode? but with PKCE flow. As it is not recommended to store client secrets on a front-end application, how can my front-end application (React) authenticate with my Rails api-only backend to authenticate with no sign-in page on the Rails side?
Is there a way to only allow third-party (non-trusted) applications to authenticate via OAuth with no user credentials interaction but allow trusted applications to pass user credentials in the body to authenticate all while using the PKCE grant flow?