Re: [OAUTH-WG] Refresh Token Expiration

2018-11-23 Thread Thomas Broyer
Just tested my OpenID Connect Session Management implementation with Safari 12.0.1 and it works like a charm. On Thu, Nov 22, 2018 at 8:09 PM George Fletcher wrote: > My understanding is that cookies are not blocked on redirects > (IPT2/Safari) but I haven't done extensive testing. So from a ful

Re: [OAUTH-WG] Binding Access Tokens is not enough!

2018-11-23 Thread Neil Madden
Thanks for doing this Daniel, I think the proposed text is good. — Neil > On 22 Nov 2018, at 14:42, Daniel Fett wrote: > > Hi all, > > I would like to discuss a text proposal for the security BCP. > > Background: > > Yesterday, Neil pointed out the following problem with binding access token

Re: [OAUTH-WG] Refresh Token Expiration

2018-11-23 Thread Reman Child
Thomas, did you test with ITP Debug Mode? If you haven't seen it, this is how to set it up: https://webkit.org/blog/8387/itp-debug-mode-in-safari-technology-preview-62/ When I tested a couple months ago, the iframe flows were the ones that were most affected by ITP2 - the hidden iframe token refre