Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Re-authentication before performing security-sensitive ops #400

Open
nvoutsin opened this issue Nov 3, 2024 · 0 comments
Open

Re-authentication before performing security-sensitive ops #400

nvoutsin opened this issue Nov 3, 2024 · 0 comments

Comments

@nvoutsin
Copy link
Contributor

nvoutsin commented Nov 3, 2024

Following #384, an optional step-up authentication mechanism should be introduced to enhance session protection and add additional safety measures before accessing higher-security areas of the app. Re-authentication may be triggered in various situations, such as: (a) before issuance, when reusing an access token; (b) before sharing data with verifiers; or (c) before other critical operations in the settings menu, e.g., account deletion (see also #317)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant