Comment 18 for bug 1041396

Revision history for this message
Mark McLoughlin (markmc) wrote : Re: Token validation includes revoked roles

I don't think leaving the current behaviour is acceptable for stable/essex

Ideally, the behaviour change to fix this wouldn't be so violent, but I think we're unlikely to break any clients here ... clients can't really assume their token won't be invalidated at any point and removing roles etc. doesn't happen often

So, yeah - fine by me for stable/essex