You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since I don't think that there is a general recommendation we could provide and there was no resonance on the mailing list, I'll postpone this topic for a potential second version of the security BCP.
I couldn't find any text in the current document about the lifetime of authorization codes, but this may be worth mentioning?
The only guidance we’re aware of on authorization code lifetimes is RFC 6749, 4.1.2:
Feedback from vendors (on the FAPI WG) seemed to be that they default to shorter lifetimes.
Shorter lifetimes seem like they can prevent various attacks, particularly if the AS isn't enforcing single-use of authorization code.
The text was updated successfully, but these errors were encountered: