Hi @aaronpk, do you know if any OAuth provider like Okta allows to set refresh tokens as HttpOnly cookie and whose token endpoint reads that cookie? Asking for a browser-based public client which can't safely store refresh tokens outside of memory otherwise.
1
That's non-standard behavior so I'm not sure anyone is doing that. But there is some discussion about bringing this idea into the working group for standardization.
1
1
Yep I agree, there's a draft I'm planning on taking to the group to suggest exactly this.
Nov 27, 2020 · 12:06 AM UTC
1

