Security and privacy, in practice
Keycloak part 1: reading the login URL, parameter by parameter
I froze the redirect Spring sends you through and read it parameter by parameter. Three lookalike strings turned out to close three different attacks, and PKCE was already on without me asking for it.