This repository was archived by the owner on Jun 12, 2021. It is now read-only.
Commit 021156c
committed
The jti parameter in a JWS should be used to catch reuse.
Need a database to hold all the jtis I've seen.
Audience in a private_key_jwt JWS is endpoint dependent.
It should not be possible to use a private_key_jwt constructed to be used
at one endpoint to be used at another.
Bumped version1 parent 573fef3 commit 021156c
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
0 commit comments