-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Labels
SecurityChanges that enhance security or fix security-related issues.Changes that enhance security or fix security-related issues.
Description
Description
As discussed here, the Pre-Authorized Code is currently not short-lived and single-use which is a hard requirement as described here.
Motivation
This feature is an important security requirement as described in OPenID4VCI
Resources
- feat: support the OpenID4VCI Authorization Code Flow #203 (comment)
- https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0-15.html#section-4.1.1-5.2.2.1
To-do List
- Make Pre-Authorized Code single use
- Make Pre-Authorized Code short-lived
Metadata
Metadata
Assignees
Labels
SecurityChanges that enhance security or fix security-related issues.Changes that enhance security or fix security-related issues.