Include the intended audiences?

Issue #14 resolved
Nat Sakimura repo owner created an issue

At this point, it might be a good idea to include the following in the Request Object as the Client intent:

  • Authorization Endpoint URI
  • Token Endpoint URI
  • (Resource Endpoint URI)

With it, it will be pretty secure.

Comments (1)

  1. Log in to comment