[Openid-specs-ab] Issue #1311: Require refresh tokens (openid/connect)

Edmund Jay issues-reply at bitbucket.org
Thu Aug 19 08:57:08 UTC 2021


New issue 1311: Require refresh tokens
https://bitbucket.org/openid/connect/issues/1311/require-refresh-tokens

Edmund Jay:

Comments from TL regarding for [pull request #39](https://bitbucket.org/openid/connect/pull-requests/39/merging-cp-into-ca)

[https://bitbucket.org/openid/connect/pull-requests/39/merging-cp-into-ca#comment-238239634](https://bitbucket.org/openid/connect/pull-requests/39/merging-cp-into-ca#comment-238239634)

* why is the refresh token optional? It’s good security practice and not requiring it makes interop difficult.

‌




More information about the Openid-specs-ab mailing list