Ticket #54 (closed enhancement: fixed)
Add TTL check to request token handling at SPs
| Reported by: | http://blog.nerdbank.net/ | Owned by: | http://blog.nerdbank.net/ |
|---|---|---|---|
| Priority: | major | Milestone: | v3.0.3 |
| Component: | OAuth | Version: | v3.0.0 RTW |
| Keywords: | SP | Cc: |
Description
Request tokens should be short-lived as a security mitigation. DNOA currently relies on the SP to do this work, but DNOA can help enforce this by adding an age check, and have a host-configurable TTL for the request tokens.
Change History
Note: See
TracTickets for help on using
tickets.
![(please configure the [header_logo] section in trac.ini)](http://nerdbank.org/RP/images/logo/dotnetopenid_tiny.gif)