Skip to content

Identify user associated to the access token #81

Description

@bitbucket-import-issues

Originally submitted by pameladingle (Pamela Dingle) on 2017-03-23

The read-only spec section 6.2.1 says a resource server "shall identify the associated user to the access token;". But what if the subject isn't a user? What if this particular request is from a legitimate non-human subject?, such as a client application making a B2B call? It is perfectly valid for API security regimes to use 2-legged schemes to access financial APIs, is this simply considered out of scope?


Bitbucket status: resolved

Bitbucket origin: issue 81

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions