Skip to content
This repository has been archived by the owner on Apr 13, 2020. It is now read-only.

Don't expose Refresh token to UI #17

Open
jeevasusej opened this issue Jan 30, 2020 · 1 comment
Open

Don't expose Refresh token to UI #17

jeevasusej opened this issue Jan 30, 2020 · 1 comment

Comments

@jeevasusej
Copy link

We should not expose refresh token to the UI. Right?

How would you handle it in right way?

https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/

@lurumad
Copy link
Collaborator

lurumad commented Jan 30, 2020

Hi @jeevasusej

It was not a good idea to create this project because at that moment we didn’t know the security concerns about ROPC flow and of course use refresh tokens in public clients.

I think we should remove this repo.

Regards!

/cc @CarlosLanderas

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants