Messages 2.1.1.1.2, etc. - Possible changes to max_age

Issue #744 resolved
Michael Jones created an issue
  1. Should we move max_age up from being in the id_token member of the request object to being a top-level member of the request object?

  2. Should we allow max_age to be specified a request parameter without using the request object?

  3. Should requesting max_age have a side effect of requiring the auth_time claim?

Comments (2)

  1. Log in to comment