Skip to content

Conversation

@jasonraimondi
Copy link
Owner

No description provided.

  - Add client_id to ParsedRefreshToken interface for validation
  - Enforce client ownership validation during token revocation
  - Return silent 200 responses for invalid tokens instead of errors
  - Handle decode errors gracefully per RFC 7009 section 2.2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants