generated from martinthomson/internet-draft-template
-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Description
A short lived id-jag token mitigates many threats such as token theft and the need to implement token revocation mechanisms, among others (although other mitigations in place such as client auth)
Should the security considerations or somewhere in the spec specificy that the token should be short lived? Sorry if this was already present and I missed it, or if it will be present in the pending Refresh token updates.
Metadata
Metadata
Assignees
Labels
No labels