OAuth2 / OIDC for Spring backends of SPAs and mobile apps: the Spring Security beans the official starters leave to you (authorities, CORS, 2xx/401 for fetch, CSRF cookie, validated redirects, logout, one refresh flow at a time), as properties.
★ 673