Skip to content

OAuth client: keep refresh_token on non-rotating refresh; restore same-origin issuer binding#2946

Merged
maxisbey merged 1 commit into
mainfrom
bughunter/oauth-followups-2
Jun 22, 2026
Merged

OAuth client: keep refresh_token on non-rotating refresh; restore same-origin issuer binding#2946
maxisbey merged 1 commit into
mainfrom
bughunter/oauth-followups-2

Carry an omitted refresh_token forward on refresh (RFC 6749 §6)

53c04e3
Select commit
Loading
Failed to load commit list.