oauth-wg / oauth-transaction-tokens

MIT License
7 stars 10 forks source link

Privacy section improvements #83

Closed tulshi closed 3 months ago

tulshi commented 3 months ago

From Yaron's feedback email: 10.1: salted SHA256. 10.1: also, in most cases txn tokens MUST NOT be logged because they contain PII (e.g. a subject that's an email address).