adorsys / adorsys/open-banking-gateway

Code2Token (confirmConsent) should use secret code to activate consent

Offen
#628 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
BE low priority
Vorherrschende Sprache
Java
Sterne
338
Forks
122
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Currently, `confirmConsent` uses authorization-id that is shared with the client device to activate consent. We need to heighten the security so that one needs a secret code additionally like in Ouath2 to activate the consent. This code should be returned on 202 listAccounts/listTransactions.
This means that `confirmConsent` should accept both auth-id and secret-code to activate consent and the secret code is returned to FinTech on initiating call (i.e. listAccounts)

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.