OAuth2.0机密与公开客户端的区别、判定依据及场景咨询
Hey there! Let's break down your OAuth 2.0 questions clearly and concisely:
1. Confidential vs. Public Clients: Differences & Classification Criteria
First, let's cover the core distinctions between these two client types, plus how to determine which category a client falls into:
Key Differences
- Confidential Clients: These are clients that can safely store a client secret without risk of exposure. They operate in controlled, trusted environments (like server-side applications where only backend teams have access to the secret). Examples include traditional web apps with server-side logic, backend APIs, or enterprise desktop apps with secure credential storage.
- They can use OAuth 2.0 flows that require a client secret, such as the standard Authorization Code Flow.
- Public Clients: These clients cannot securely protect a client secret because they run in environments accessible to end-users (and potential attackers). Examples include single-page apps (SPAs) running in browsers, mobile apps, or native desktop apps that can be decompiled or inspected.
- They rely on secret-free flows like Authorization Code Flow with PKCE (Proof Key for Code Exchange) — the recommended modern approach — or the now-discouraged Implicit Flow.
How to Classify a Client
The primary criterion is whether the client can maintain the confidentiality of its credentials. Ask yourself:
- Can the client environment prevent unauthorized access to the client secret? (e.g., server-side code is hidden from end-users)
- Is the client's code or storage accessible to end-users? (e.g., an Android APK can be decompiled, browser JavaScript can be inspected)
If you can securely safeguard the secret, it’s a confidential client. If not, it’s a public client.
2. StackOverflow's "Login With Google" Client Type
StackOverflow's "Login With Google" is a confidential client. Here’s why:
StackOverflow runs as a server-side web application. When you click "Login With Google", your browser redirects to Google’s auth server, but once you grant permission, Google sends an authorization code to StackOverflow’s backend. StackOverflow then uses its securely stored client secret to exchange that code for an access token with Google’s token endpoint. Since the secret is never exposed to end-users (it lives only on StackOverflow’s servers), it fits the confidential client definition.
3. Android App's "Login With Google" Client Type
An Android app’s "Login With Google" implementation is a public client. Even though Android apps use app signing to verify authenticity, a client secret can’t be safely stored in the app itself — APKs can be decompiled, and any hardcoded secrets would be exposed. Instead, Android apps use the Authorization Code Flow with PKCE, which eliminates the need for a client secret. PKCE adds security by generating a unique code verifier for each auth request, preventing authorization code interception attacks.
内容的提问来源于stack exchange,提问作者Mangu Singh Rajpurohit

