Skip to content

Verify DPoP Proof public key during refresh_token grant for public clients #1949

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
jgrandja opened this issue Mar 25, 2025 · 0 comments
Closed
Assignees
Labels
type: enhancement A general enhancement
Milestone

Comments

@jgrandja
Copy link
Collaborator

jgrandja commented Mar 25, 2025

For public clients during the refresh_token grant flow, the DPoP Proof PublicKey must be the same as the access token PublicKey binding.

Related gh-1813

@jgrandja jgrandja added the type: enhancement A general enhancement label Mar 25, 2025
@jgrandja jgrandja self-assigned this Mar 25, 2025
@jgrandja jgrandja added this to the 1.5.0-RC1 milestone Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: enhancement A general enhancement
Projects
None yet
Development

No branches or pull requests

1 participant