Migrating oidc-client-js to use the OpenID Connect Authorization Code Flow and PKCE
recommendation of abandoning the implicit flow in browser-based applications, e.g. Single Page Applications (SPAs), in favor of the authorization code flow with Proof-Key for Code Exchange (PKCE)