OWASP ASVS 5.0 section 10.4.8 requires strict refresh token expiry, which conflicts with FAPI 2.0 SP 5.3.2.1-9
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 活跃
调研方向
首先比较 OWASP ASVS 5.0 第 10.4.8 节与 FAPI 2.0 Security Profile 5.3.2.1-9,即 issue 中提到的两个参考。确定这些要求是否确实存在冲突,并记录达成一致的解释或规范变更;完成取决于解决这一标准问题。
由索引模型根据 Issue 内容生成。
描述
It says
10.4.8 Verify that refresh tokens have an absolute expiration, including if sliding refresh token expiration is applied.
(Source) OWASP ASVS 5.0 https://github.com/OWASP/ASVS/tree/v5.0.0#latest-stable-version---500
This is contrary to FAPI 2.0 Security Profile 5.3.2.1-9 that states "shall not use refresh token rotation except in extraordinary circumstances"
- 主要语言
- HTML
- 星标
- 4
- 派生
- 3
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
openid/fapi 的其他 Issue
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
难度 2/5 1-3 小时 新手友好度 62/100
-
migrated-from-bitbucket priority: trivial type: bug
难度 2/5 1-3 小时 新手友好度 78/100
-
detecting inconsistent .well-known/openid-configuration vs .well-known/oauth-authorization-server on conformance tests可能已有人在做 @jogu 于 6 天前认领。 未关闭component: Certification component: FAPI2: Advanced Authorization
难度 5/5 一周以上 新手友好度 35/100
-
component: Certification component: FAPI2: Security Profile
难度 4/5 3-5 天 新手友好度 35/100
-
last_updated_at vs last_update可能重新可做 @dpostnikov 于 34 天前认领,目前没有进行中的 PR。 未关闭component: Grant Management
相似的 Issue
-
documentation good first issue hacktoberfest help wanted jsdoc
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
vector-store
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 88/100
维护者通常 1 天内回复
-
triage/confirmed
难度 2/5 1-3 小时 新手友好度 78/100
agentscope-ai/agentscope#3032 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
objectionary/eoc#1396 ·
维护者通常 1 天内回复