Why use state, or even nonce?

A post was merged into an existing topic: SPA’s don’t do authentication (replay attacks)