Open
Description
Is anyone working on OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) support? RFC 9449 https://datatracker.ietf.org/doc/html/rfc9449 was published 2023.
This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks with access and refresh tokens
Of course, the API will have to go through the Go change proposal process. (If it helps anyone, here's an example of a previous oauth2 proposal golang/go#58126.)
Metadata
Metadata
Assignees
Labels
No labels