Skip to content

Support RFC 8707, resource indicators #1767

Open
@mooreds

Description

@mooreds

Support RFC 8707, resource indicators

Problem

An access token can be presented to any resource server. This is an issue if the token is exfiltrated.

Solution

Have clients provide information about which resource server they are requesting access to, using standards.

Alternatives/workarounds

n/a

Additional context

Here's the RFC: https://datatracker.ietf.org/doc/html/rfc8707

Community guidelines

All issues filed in this repository must abide by the FusionAuth community guidelines.

How to vote

Please give us a thumbs up or thumbs down as a reaction to help us prioritize this feature. Feel free to comment if you have a particular need or comment on how this feature should work.

Metadata

Metadata

Assignees

No one assigned

    Labels

    standardsIssues that refer to IETF, W3C or other standards

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions