oauth-wg/oauth-transaction-tokens

Privacy section improvements

Closed this issue · 0 comments

From Yaron's feedback email:
10.1: salted SHA256.
10.1: also, in most cases txn tokens MUST NOT be logged because they contain PII (e.g. a subject that's an email address).