Skip to content

[RFC] Disable Password Credentials and Implicit grants by default #259

@ajgarlag

Description

@ajgarlag

These grants are marked as 'legacy' on the oAuth.net website and their usage is discouraged in the OAuth 2.0 Security Best Current Practice document.

I propose updating the Flex recipe to disable these grants for new installations and setting the default values of enable_password_grant and enable_implicit_grant to false in version 2.0.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions