V51 - OAuth - DPoP proof replay attack protection #2188
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
V51
Group issues related to OAuth
Will be closed if no response/opposite arguments
_5.0 - prep
This needs to be addressed to prepare 5.0
Should we add some requirement about DPoP proof replay attack protection?
Possible concrete mitigations:
FAPI 2.0 does not require the usage of DPoP server-side nonce:
FAPI 2.0 has this requirement about "iat" validation (which is valid applicable to DPoP and other JWTs as well) but this actually does not help so much for our purpose:
The text was updated successfully, but these errors were encountered: