You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Section 6.1 states that the token endpoint response MAY include the auth_session parameter. This is required for messages returned from the AS, I am unclear why it is not required when a token endpoint response is returned. Section 6.2 has the same issue.
The text was updated successfully, but these errors were encountered:
The intent was that this is an optional feature of the protocol. The authorization server may not want or need to maintain context, so it becomes optional in that sense. I do expect it will be commonly used, but the protocol can be used without it. It may also be included in the token response (even when the authorization code was obtained through other means), but not mandatory as existing AS's may not support it.
Section 6.1 states that the token endpoint response MAY include the auth_session parameter. This is required for messages returned from the AS, I am unclear why it is not required when a token endpoint response is returned. Section 6.2 has the same issue.
The text was updated successfully, but these errors were encountered: