oauth2-server
oauth2-server copied to clipboard
Control over issuing refresh tokens
It should be possible to control the provision of refresh tokens.
Particular policies that would likely be useful:
- Include/exclude for particularly non-/sensitive scopes.
- Include/exclude for particularly non-/trusty-worthy clients.