View Issue Details

IDProjectCategoryView StatusLast Update
0008717CTT UA Test Case3 - Feature Requestpublic2023-04-13 16:12
ReporterJim Luth Assigned ToPaul Hunkar  
PrioritynormalSeverityminorReproducibilityalways
Status acknowledgedResolutionopen 
Summary0008717: 6.5.3.2 Access Tokens
Description

Need to explicitly define requirements for expired tokens.

TagsBSI
Files Affected

Relationships

related to 0007199 closedMatthias Damm 10000-004: Services 6.5.3.2 Access Tokens 

Activities

Randy Armstrong

2023-02-28 17:35

administrator   ~0018813

Clarify when to honor token validity expiration. Add remark to Part 4 (7.36.6 IssuedIdentityToken) regarding this behavior.

Matthias Damm

2023-02-28 17:35

reporter   ~0018814

Need input from Randy to continue

Randy Armstrong

2023-02-28 17:35

administrator   ~0018815

Not sure what input is needed. AccessTokens expire. When they expire Session credentials should be revoked.

Clients that use AccessTokens need to be aware of the expiry time and call ActivateSession with a new token prior to expiry of the existing Token if they want uninterrupted access.

Matthias Damm

2023-02-28 17:35

reporter   ~0018816

Added following clarification to 7.41.6 IssuedIdentityToken

IssuedIdentityTokens have an expiration time, and a Server shall reject the credentials of the Session after the expiration of the token. The Session shall stay valid with an Anonymous user token if the Server allows Anonymous users. Clients should renew the token with ActivateSession before the expiration time to avoid communication interruption.

Jim Luth

2023-02-28 17:35

administrator   ~0018817

Agreed to 1.05 text. Needs 1.04 Errata to close.

Paul Hunkar

2023-04-13 16:11

administrator   ~0019179

Need to define test cases for this cloned issue

Issue History

Date Modified Username Field Change
2023-02-28 17:35 Jim Luth New Issue
2023-02-28 17:35 Jim Luth Tag Attached: BSI
2023-02-28 17:35 Jim Luth Issue generated from: 0007199
2023-02-28 17:35 Jim Luth Note Added: 0018813
2023-02-28 17:35 Jim Luth Note Added: 0018814
2023-02-28 17:35 Jim Luth Note Added: 0018815
2023-02-28 17:35 Jim Luth Note Added: 0018816
2023-02-28 17:35 Jim Luth Note Added: 0018817
2023-02-28 17:35 Jim Luth Relationship added related to 0007199
2023-02-28 17:35 Jim Luth Project 10000-004: Services => Compliance Test Tool (CTT) Unified Architecture
2023-02-28 17:35 Jim Luth Category Spec => Api Change
2023-04-13 16:10 Paul Hunkar Project Compliance Test Tool (CTT) Unified Architecture => CTT UA Test Case
2023-04-13 16:11 Paul Hunkar Category Api Change => 3 - Feature Request
2023-04-13 16:11 Paul Hunkar Note Added: 0019179
2023-04-13 16:12 Paul Hunkar Assigned To => Paul Hunkar
2023-04-13 16:12 Paul Hunkar Status new => acknowledged