Skip to content

Add security consideration on refresh tokens? #130

Open
@PieterKas

Description

@PieterKas

Based on discussion with Brian - should we give guidance on refresh tokens?

We should only add anything if there is new information. Currently it is not clear that we should. RFC 7521 already defines this.

"Implementation of this specification should treat refresh tokens in accordance with RFC 7521"

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions