On Sun, May 16, 2010 at 11:27 AM, Dick Hardt <[email protected]> wrote:
> Torsten: enabling a client to revoke a refresh token looks like a useful > mechanism. I anticipate it will be viewed as a vitamin feature rather than a > painkiller and will fall by the wayside unless the security conscience rally > to have it included. > I’d like to put in another vote for this mechanism. I’m about to add a “in-app logout” to an iPhone app that uses OAuth; while I can delete the token from the device, a standard way for deleting the token from the web service would be helpful in preventing future uses of the token (for example, if the device is restored from a backup and the token was stored in the backup files). -Chasen
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
