1. 27 Jul, 2020 1 commit
    • Drew Blessing's avatar
      Revoke OAuth grants when a user revokes an application · 9e9d97f7
      Drew Blessing authored
      Currently, when a user revokes OAuth applications only
      existing access tokens are revoked. If an application has already
      requested a code (grant) to later redeem for an access token, the
      grant may remain valid and will generate a valid access token
      until expired (10 min expiry). This change ensures both access
      tokens *and* grants are revoked when a user revoked the application.
      9e9d97f7
  2. 24 Jul, 2020 39 commits