Versões comparadas

Chave

  • Esta linha foi adicionada.
  • Esta linha foi removida.
  • A formatação mudou.

...

In addition, the confidential client

  1. shall support encrypted request objects;shall support Pushed Authorisation Requests PAR;

  2. shall support parameterized OAuth 2.0 resource scope consent as defined in clause 6.3.1 OIDF FAPI WG Lodging Intent Pattern;

  3. shall support refresh tokens;

  4. shall not populate the acr claim with required values;

  5. shall require the acr claim as an essential claim;shall support all authentication methods specified in clause 5.2.2-14 of Financial-grade API Security Profile 1.0 - Part 2: Advanced including diferent combinations of the methods to send requests (using PAR or not - item 11);

  6. shall not allow refresh tokens rotation feature;

  7. shall send header x-fapi-interaction-id on FAPI endpoints;

...