-
Notifications
You must be signed in to change notification settings - Fork 36
Open
Labels
iaeItems related to Interactive Authorization EndpointItems related to Interactive Authorization Endpoint
Description
- In the case of multiple redirect_to_web interactions, does the IAE return fresh request_uri values or always return the same request_uri? For comparison, Section 4 of RFC 9126 (Authorization Request) states: "[...] the client MUST only use a request_uri value once. Authorization servers SHOULD treat request_uri values as one-time use but MAY allow for duplicate requests due to a user reloading/refreshing their user agent."
Metadata
Metadata
Assignees
Labels
iaeItems related to Interactive Authorization EndpointItems related to Interactive Authorization Endpoint