Remove Client Secrets from configuration and saslStart

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 7.0.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Minor Change
    • Security 2023-04-03
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      We should not accept a Client Secret in our OAuth2 configuration. We are a public client, so we should not allow the Authorization Server to allocate a secret and potentially believe we are a confidential client.

            Assignee:
            Spencer Jackson
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: