cloudfoundry / cloudfoundry/uaa-release

In mid 2018 is the default "refreshTokenFormat":"jwt", "refreshTokenUnique":false the best approach?

Open
#93 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

unscheduled
Dominant language
Ruby
Stars
28
Forks
77
Avg merge
1d 3h
Merged PRs (30d)
14

Description

This story seems to chronologically pre-date cf-deployment. Is it still the best thing for everyone to use JWT and "refreshTokenUnique":false by default?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the linked Pivotal Tracker story, uaa-release commit a717b527de6de180b8b8c7b5c82b99174da524e3, and referenced Slack thread. Compare the historical rationale for refreshTokenFormat=jwt and refreshTokenUnique=false with current cf-deployment usage, then establish whether a default change is warranted and record the decision.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.