top | item 29101555

(no title)

brokenwren | 4 years ago

So, do you know of anyone that has written this type of thing up? I'd love to have some fodder when having these types of discussions. :)

discuss

order

detaro|4 years ago

Hm, not specifically. OAuth2 specifications and documentation sort of address the motivation for Refresh Tokens at least (and are widely written about in blog posts etc) - and I think the security recommendations documents now strongly push for Refresh Tokens. For the benefit of automated refresh one could also pull the Let's Encrypt arguments as "similar enough" and widely recognized as good practice.