关于RFC 6749中授权码流与隐式授权流图(B)环节双向箭头的技术疑问
Great question—this is a super common point of confusion when first diving into OAuth 2.0 flow diagrams, and the bidirectional arrow isn't a mistake! Let me break down why it's there:
What the Bidirectional Arrow Actually Represents
The (B) step labeled "Authorization Server authenticates the Resource Owner via the User-Agent" isn't a single one-way action—it's a two-part interactive exchange between the resource owner and authorization server, mediated by the user-agent (like a web browser):
- First, the authorization server sends an authentication prompt (login form, MFA challenge, etc.) to the resource owner through the user-agent (this is the arrow pointing to the resource owner).
- Then, the resource owner provides their credentials (username/password, security code, etc.) and submits them back to the authorization server via the user-agent (this is the arrow pointing from the resource owner to the server).
RFC 6749 uses the bidirectional arrow to condense these two back-and-forth actions into a single labeled step (B), rather than cluttering the diagram with two separate arrows.
Why Your Single Arrow Only Captures Part of the Picture
Your modified diagram with a one-way arrow from the resource owner to the server makes sense if you're only thinking about the user submitting credentials—but it misses the first half of the interaction: the authorization server initiating the authentication request by presenting the login interface to the user. The full (B) step requires both directions to be complete.
A Real-World Example
Think about when you log into a third-party app using Google:
- You click "Login with Google" (step A).
- Google's authorization server loads a login page in your browser (server → user part of step B).
- You enter your Google password and click "Allow" (user → server part of step B).
- Google sends the authorization code back to the app (step C).
That entire back-and-forth in steps 2 and 3 is exactly what the bidirectional arrow in RFC 6749's diagram is representing.
So to sum up: the bidirectional arrow is intentional—it's a shorthand for the full interactive authentication flow between the resource owner and authorization server, not a single one-way message.
内容的提问来源于stack exchange,提问作者runningwild

