OAuth 2.0 Token Revocation

OAuth 2.0 Token Revocation
复制标题

OAuth 2.0 令牌撤销

DOI:
10.17487/rfc7009
复制
发表时间:
2013
期刊:
RFC
影响因子:
--
通讯作者:
Marius Scurtescu
Marius Scurtescu
中科院分区:
--
文献类型:
--
作者:
T. Lodderstedt;Stefanie Dronia;Marius Scurtescu

文献摘要

被引文献

相似文献

本文提出了一个用于OAuth授权的附加端点 服务器,允许客户端通知授权服务器, 不再需要先前获得的刷新或访问令牌。 这允许授权服务器清除安全凭据。 撤销请求将使实际令牌无效,如果 适用于基于相同授权授予的其他令牌。
This document proposes an additional endpoint for OAuth authorization servers, which allows clients to notify the authorization server that a previously obtained refresh or access token is no longer needed. This allows the authorization server to clean up security credentials. A revocation request will invalidate the actual token and, if applicable, other tokens based on the same authorization grant.