oauth-wg / oauth-transaction-tokens

MIT License
7 stars 10 forks source link

Using Txn-Tokens securely #49

Closed tulshi closed 5 months ago

tulshi commented 8 months ago

We need to add in the Security Considerations section, information on how services may use Txn-Tokens securely, by possibly using them in conjunction with SPIFFE or other service-to-service security mechanisms.

(based on feedback by Kai Lehmann (@obfuscoder))

tulshi commented 7 months ago

21 talks about the same issue, but this is a broader statement.

tulshi commented 5 months ago

We will use a new header named "Txn-Token"