Uploaded image for project: 'FTS'
  1. FTS
  2. FTS-1846

FTS should include "requested_token_type" claim in OAuth2 Token Exchange

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • fts-rest-server 3.12.0
    • fts-rest-server 3.12.1
    • FTS-Flask
    • Security Level: Public Data (This ticket is visible to anyone on the internet and will be indexed by search engines)
    • None

    Description

      Discovered during FTS + CILogon TokenProvider integration.

      FTS should include the "requested_token_type: 
      urn:ietf:params:oauth:token-type:refresh_token" claim during the token exchange request to ensure he TokenProvider will return a refresh token. Without this claim, the TokenProvider is free to also return a new access token.

      Attachments

        Activity

          People

            mipatras Mihai Patrascoiu
            mipatras Mihai Patrascoiu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: