Annotate
mod_lib_ldap/dev/TODO.md @ 5512:1fbc8718bed6
mod_http_oauth2: Bind refresh tokens to client
Prevent one OAuth client from using the refresh tokens issued to another
client as required by RFC 6819 section 5.2.2.2
See also draft-ietf-oauth-security-topics-22 section 2.2.2
Thanks to OAuch for pointing out this issue
author |
Kim Alvefur <zash@zash.se> |
date |
Fri, 02 Jun 2023 10:40:48 +0200 |
parent |
809:1d51c5e38faa |
rev |
line source |
809
|
1 * Make groups optional
|
|
2 * Make groups work with both posixGroup and groupOfNames
|