w3c / automotive

W3C Automotive Working Group Specifications
Other
146 stars 68 forks source link

Sending the JTI instead of the whole access token to save bandwidth #419

Closed isaacagudo closed 2 years ago

isaacagudo commented 2 years ago

As discussed in issue #399, we want to have the possibility to send a short token to authorize requests to the server. As agreed in the last meeting, sending just the JTI seems like a reasonable solution. I tried to change as little as possible in the specification. I could elaborate a bit more on the caching strategy for the server but I think this is out of the scope.