File

mod_http_oauth2/html/device.html @ 6326:17d9533f7596

mod_http_oauth2: Reject invalid attempt to register client without credentials The implicit flow works without a client_secret since the token is delivered directly, but all other currently supported grant types require client to authenticate using credentials, so it makes no sense to not issue credentials then.
author Kim Alvefur <zash@zash.se>
date Thu, 03 Jul 2025 15:45:00 +0200
parent 5653:401356232e1b
line wrap: on
line source

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>{site_name} - Authorize{client&d} Device</title>
<link rel="stylesheet" href="style.css" />
</head>
<body>
{error&
	<dialog open="" class="error">
		<p>{error.text}</p>
		<form method="dialog"><button>dismiss</button></form>
	</dialog>}
	<header>
	<h1>{site_name}</h1>
	</header>
	<main>
	<fieldset>
	<legend>Device Authorization</legend>
{client&
	<p>Authorization completed. You can go back to
	<em>{client.client_name}</em>.</p>}
{client~
	<p>Enter the code to continue.</p>
	<form method="get">
		<input type="text" name="user_code" placeholder="XXXX-XXXX" aria-label="Code" required="" />
		<button type="submit">Continue</button>
	</form>}
	</fieldset>
	</main>
</body>
</html>