Make the permission ticket optional when "upgrading" the RPT for an UMA-native refresh flow
xmlgrrl opened this issue · 0 comments
xmlgrrl commented
James brought up the idea of a kind of client-to-AS-first UMA-native refresh flow, where no policy context is needed, came up in UMA telecon 2017-08-23, but we didn't have time to consider it fully at this stage in V2.0.
We did discuss our original motivation for wanting to ensure that a regular old OAuth refresh token and refresh flow "just works" as expected, and we made some decisions in this call confirming how that should go.