sender-constrained auth codes & refresh tokens: what does it mean?

Issue #342 resolved
Brian Campbell created an issue

Baseline has "shall only issue authorization codes and refresh tokens that are sender-constrained "

What's the intent of having this? The two previous items requiring client auth and PKCE mean a priori that the RT is sender-constrained and the auth code is sender-constrained twice. But this text maybe suggests something else. Or is redundant. I'm not sure.

Comments (3)

  1. Log in to comment