- https://www.rfc-editor.org/rfc/rfc6749.html: The OAuth 2.0 Authorization Framework
- https://www.rfc-editor.org/rfc/rfc6750.html: The OAuth 2.0 Authorization Framework: Bearer Token Usage
- https://www.rfc-editor.org/rfc/rfc6749.html: The OAuth 2.0 Authorization Framework
- https://www.rfc-editor.org/rfc/rfc6750.html: The OAuth 2.0 Authorization Framework: Bearer Token Usage
I mean, you might say “but you should” or “it would actually help” or “in an ideal world…” but it is still, realistically, not going to happen.
I certainly don't want people building security sensitive parts of an app to be slinging the features out.
you do you, i guess.
but that's where the source of truth about how oauth 2.0 works is.
the "why" you're looking for it's in there.
how it's implemented... well that's an implementation detail, that most often one couldn't understand without the domain knowledge (unless it's something "trivial" like an off-by-one in some string comparison or something like that).
The "implementation details" are what we're tasked with implementing ;)
Search engine > Encyclopedia