On Sun, May 16, 2010 at 11:27 AM, Dick Hardt <[email protected]> wrote:

> Torsten: enabling a client to revoke a refresh token looks like a useful
> mechanism. I anticipate it will be viewed as a vitamin feature rather than a
> painkiller and will fall by the wayside unless the security conscience rally
> to have it included.
>

I’d like to put in another vote for this mechanism.

I’m about to add a “in-app logout” to an iPhone app that uses OAuth; while I
can delete the token from the device, a standard way for deleting the token
from the web service would be helpful in preventing future uses of the token
(for example, if the device is restored from a backup and the token was
stored in the backup files).
-Chasen
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to