aaronpk / draft-parecki-oauth-client-id-metadata-document

Other
1 stars 1 forks source link

Caching recommendations for the metadata document #3

Open aaronpk opened 4 months ago

aaronpk commented 4 months ago

https://drafts.aaronpk.com/draft-parecki-oauth-client-id-metadata-document/draft-parecki-oauth-client-id-metadata-document.html#name-metadata-caching

Probably makes sense to respect the HTTP cache headers from the metadata URL.

The AS should probably also have its own min/max cache lifetime policy. Not sure if we want to recommend something explicit here though since it might depend on the particular deployment.