A security engineer is reviewing a cloud application that uses OAuth 2.0 to delegate access to a third-party API. The application is a single-page application (SPA) running in the browser. The engineer wants to prevent authorization code interception and ensure that the client cannot impersonate another client. Which OAuth 2.0 enhancement should be implemented?
PKCE mitigates authorization code interception attacks by requiring the client to send a code verifier that matches a previously sent code challenge. This binds the authorization code to the client that initiated the request, preventing an attacker who intercepts the code from exchanging it. For SPAs, which cannot securely store client secrets, PKCE is the recommended enhancement.
Why this answer
PKCE is specifically designed to secure the authorization code flow for public clients like SPAs that cannot hold a client secret. It prevents code interception by binding the code to a dynamically generated verifier. The implicit flow, client credentials, and resource owner password credentials either expose tokens or require secrets that SPAs cannot protect, and none address code interception.
Exam trap
The trap here is assuming that OIDC or the implicit flow solves SPA security, when PKCE is the required enhancement for the authorization code flow in public clients.