If a client presents an access token where the "aud" claim is an array containing more than one string, then the server should reject it.
- duplicates
-
SERVER-86603 Ensure that MongoDB Server rejects JWT tokens with multiple audience claims
- Closed
- is depended on by
-
COMPASS-7667 Investigate changes in SERVER-86607: Reject access tokens with multiple audience claims
- Closed