What is PKCE (Proof Key for Code Exchange)?
An OAuth extension that binds the authorization code to a secret the client created, blocking code interception on public clients. Mobile apps and browser-only clients should always send code_challenge with the request.
Related terms
OAuth 2.0 Authorization Code Flow
The standard delegation flow where users approve access on the provider and the app exchanges a short-lived code for tokens server-side. BYOB-managed Google sign-in hides this handshake from project developers entirely.
JWT Claims
The signed JSON assertions inside a JSON Web Token, such as subject, expiry, issuer, and role. Services trust claims only after verifying signature, issuer, audience, and expiration together.
Better Auth
Authentication with managed Google sign-in or email/password flows provisioned for generated apps. Auth pages (callbacks, sign-in) are private surfaces and stay noindexed like any other.
Cross-Site Request Forgery (CSRF)
An attack that tricks a logged-in browser into submitting unwanted state-changing requests to a trusted site. SameSite cookies, anti-CSRF tokens, and origin checks break the forgery chain.
SQL Injection
An attack that smuggles database commands through unsanitized input into application queries. Parameterized statements and least-privilege database roles keep hostile input as data, never executable code.
CSP Directives
The individual rules inside a Content Security Policy, such as script-src, object-src, and frame-ancestors. Each directive narrows one resource class, so auditing means reviewing directives one by one.