-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Description
Is anyone working on OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) support? RFC 9449 https://datatracker.ietf.org/doc/html/rfc9449 was published 2023.
This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks with access and refresh tokens
Of course, the API will have to go through the Go change proposal process. (If it helps anyone, here's an example of a previous oauth2 proposal golang/go#58126.)
theadell, joaopenteado, dmihalcik-virtru, rodafr, bnewbold and 4 more
Metadata
Metadata
Assignees
Labels
No labels