RFC-9449: DPoP by zachswasey · Pull Request #808 · authlib/authlib

Skip to content

Navigation Menu

Sign in

Appearance settings

Conversation

zachswasey

* Add DPoP extension for AuthorizationCodeGrant and RefreshTokenGrant
* Add DPoPTokenValidator for ResourceProtector
* Add DPoPProofValidator to validate proofs
* Add DPoPNonceGenerator protocol for server-side nonce creation and management
* Add DPoPNonceCache protocol for client-side nonce cache
* Add DPoPTokenGenerator for public-key bound access tokens of DPoP type
* Remove update_nonces, as nonce-loss is self-correcting

zachswasey

zachswasey

zachswasey

zachswasey

Comment on lines +54 to +62

zachswasey

Comment on lines +41 to +64

zachswasey

zachswasey

lepture