Josh Grossman

Results 775 comments of Josh Grossman

awaiting outcome of #1230

Ok so what everything in V9 has in common which is not the case for the 4 requirements you specified is that the server-side configuration would almost certainly be outside...

You think that CSRF is more of a configuration problem?

But it is a special kind of configuration which is a little outside of the regular application domain and it is also an important topic which is why I think...

Can we say "Communication Protection"?

> Can we say "Communication Protection"? @elarlang what do you think?

Ok so "Communication Encryption"? @elarlang

Created #1342 @elarlang

That makes sense although do you think saying "cannot" instead of "does not" is clearer @jmanico ? _Verify that logout and expiration invalidate the session token, such that the back...

The app is the downstream relying party. I am going to open a PR.