Dominick Baier
Dominick Baier
Hey - seems you read the spec ;)
Oh - and btw - we implemented all of that already of course client side piece here: https://github.com/DuendeSoftware/Duende.AccessTokenManagement and JwtBearer extensions here: https://docs.duendesoftware.com/identityserver/v7/apis/aspnetcore/confirmation/#validating-dpop-proof-of-possession
https://blog.duendesoftware.com/posts/20220204_admin_ui/
or rather a link to a page that we control and can update