Skip to content

Refresh Tokens not listed in accepted grant_type's #53

@nghamilton

Description

@nghamilton

Given that refresh tokens must be supported, and the /token endpoint must accept them, should refresh_token also be included in the permitted options for the grant_type claim, as specified in Client Authentication? https://consumerdatastandardsaustralia.github.io/infosec/#client-authentication currently says it must be "authorisation_code or client_credentials".

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugRepresents a bug

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions