HL7 / smart-app-launch

SMART on FHIR App Launch Protocol
24 stars 25 forks source link

best practices page edits #382

Closed Healthedata1 closed 3 years ago

Healthedata1 commented 3 years ago

I have a question about this text:

"Client architectures where data pass through or are stored in a secure backend server (e.g., many confidential clients) can offer more secure {refresh token :: client} binding,...

what is {refresh token :: client} binding ???

jmandel commented 3 years ago

what is {refresh token :: client} binding ???

This is to say: how can we ensure that only the intended client is able to use a given refresh token