Sort:  

wil be an great project.

We should push in prod today or tomorrow. To disable this simply don't ask for offline access. Only refresh tokens are concerned

Would be even more secure if we could specify available scopes for the app in the dashboard.

In the documentation there is mentioned, that refresh token (and OAuth2 code flow) is enabled only, when user agree for na 'offline' scope - does it work in different way?

good job mr

i need secure ..