Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Include token protection services in G081? #37

Open
marcvs opened this issue Oct 15, 2024 · 1 comment
Open

Include token protection services in G081? #37

marcvs opened this issue Oct 15, 2024 · 1 comment
Labels
AARC-G081 Guidelines for token lifetimes

Comments

@marcvs
Copy link

marcvs commented Oct 15, 2024

This issue was created with the document version "v1"

Services (such as vault or mytoken, we will not name them in the document) proxy a refresh token for the users and give them a proprietary token. This may help in some cases or not in other cases.

How do people feel about including such services in the doc. Do we want to add also lifetime recommendations on such services? It may derail the doc a bit, so in the current version I've only kept a very short remark.

@marcvs marcvs added the AARC-G081 Guidelines for token lifetimes label Oct 15, 2024
@marcvs marcvs changed the title Include token protection services in Go81? Include token protection services in G081? Oct 15, 2024
@msalle
Copy link

msalle commented Oct 15, 2024

It's a bit tricky because there isn't really an RFC or other standard for them, but it does follow a certain pattern that requires careful risk assessment and guidance. I'm probably in favour of adding them in a special category.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
AARC-G081 Guidelines for token lifetimes
Projects
None yet
Development

No branches or pull requests

2 participants