Skip to content

Allow "unauthorize" in broader scenarios #8

@aaronpk

Description

@aaronpk

The description of "unauthorize" is currently:

The OP sends this command when it suspects a previous OpenID Connect ID Token issued by the OP was granted to a malicious actor.

I'm not sure if this was actually intended to be defined as such a limited scope, but I don't think this should be limited to "malicious actors". It should also be allowed for other situations such as if the OP determines a device has been compromised.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions