Matt MacAdam
Matt MacAdam
We're in alignment on signin--The existing diagram doesn't go into the details of the OAuth flow, but it shows the secure session is set up after the initial signin flow....
Thought about my musings in the last post some more--the reason the internal deferral mechanism works (or at least, how it works as proposed) is because we establish during the...
The case for keeping it in the header is if there is a use case in which the user agent would need a valid access token to access the /securesession/startsession...