Skip to content

Commit 3bff1fe

Browse files
committed
removed unfinished thought
1 parent 023af4d commit 3bff1fe

File tree

1 file changed

+0
-2
lines changed

1 file changed

+0
-2
lines changed

draft-ietf-oauth-browser-based-apps.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -320,8 +320,6 @@ Additionally, cookies MUST be protected from leakage by other means, such as log
320320
This architecture protects against tokens leakage from the browser, but creates a CSRF attack vector:
321321
once the user is authenticated, the BFF proxy will automatically add tokens to calls to the resource server.
322322

323-
Cookies must be protected, not only from the browser itself using
324-
325323
<!--
326324
TODO: Add another description of the alternative architecture where access tokens are passed to JS and the JS app makes API calls directly. https://mailarchive.ietf.org/arch/msg/oauth/sl-g6zYSpJW3sYqrR0peadUw54U/
327325
-->

0 commit comments

Comments
 (0)