Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add to security concerns section #12

Open
sdesen opened this issue Jun 11, 2024 · 1 comment
Open

Add to security concerns section #12

sdesen opened this issue Jun 11, 2024 · 1 comment

Comments

@sdesen
Copy link

sdesen commented Jun 11, 2024

@kamronbatman
Copy link

kamronbatman commented Jul 9, 2024

  • We should add some kind of verbiage similar to RFC 9470 Section 9 regarding authentication/sessions.
  • We should probably add some recommendation about the lifetime of the jag token to the effect of that the token should only live as long as necessary to exchange. This is reinforced by the idea that an oauth id-token refresh token can be used to get an unexpired id token to exchange for another id jag.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants