Published a year ago
Published a year ago
LowPass
Updated a year ago
0
I have noticed that session management of OIDC authentication for example currently is not sufficient in terms of security. One can log in to a web service with SafeLine OIDC authentication step from one place, and then the next day from another place it still works without the addidional OIDC authentication. In short: session timeout is much too öong, and is not specific enough.