Skip to content

Tighten verification of access tokens #7993

@hannes-ucsc

Description

@hannes-ucsc

Once Data Browser participates in authorization code flow,

  • delete DB-specific client ID
  • verify that passed in access tokens originate from Azul's client instead of just any client in Azul's GCP project

Metadata

Metadata

Assignees

Labels

authentication[subject] Verifying account credentials

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions