Skip to content

Potential incoherent issue and expiry instants in Oauth2 tokens #6807

@ch4mpy

Description

@ch4mpy

As pointed in #6634 (and #6557), it seems possible to build tokens with issue and expiry instants and differing with what is exposed in claims (or attributes for opaque tokens).

I propose here a rather radical way to prevent this: removing issue and expiration instants members from AbstractOAuth2Token in favor of claims.

I've no illusion this PR will be rejected at this stage, just a support for discussion.

Metadata

Metadata

Assignees

Labels

in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)status: declinedA suggestion or change that we don't feel we should currently apply

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions