ory/fosite

Create test to assert JTI, at_hash, code_hash for refresh flows

Closed this issue · 3 comments

Is your feature request related to a problem? Please describe.

See #523

@mitar would you be open to tackle this?

mitar commented

I am not sure how. I would need some guideline. I could not find an existing test doing this check.

So we should have a test which would make sure that refreshed tokens do not have same JIT as the original ones.

Ok, no problem, I'll try and come up with one!

mitar commented

Have you made the fix here or have you just closed the issue?