spring-security
spring-security copied to clipboard
Document Authorization Server PKCE settings
Updates documentation to reflect that PKCE is now enabled by default for authorization_code flows in both authorization server and client.
Changes include:
- Documenting the default PKCE behavior for authorization code flows
- Adding instructions for disabling PKCE when not supported
- Adding a new
ClientSettingssection to document authorization server configuration options
The documented changes were introduced by:
- gh-16391
- gh-17507