BK Comments 5.2.1

Issue #103 resolved
Nat Sakimura repo owner created an issue

Section 5.2.1

It is possible for the Request Object to include values that are to
be revealed only to the Authorization Server. As such, the
"request_uri" MUST have appropriate entropy for its lifetime. For
the guidance, refer to 5.1.4.2.2 of [RFC6819]. It is RECOMMENDED
that it be removed after a reasonable timeout unless access control
measures are taken.

It sounds like a link to https://www.w3.org/TR/capability-urls/ mightalso be useful.

Comments (5)

  1. Log in to comment