3 ms·
"… or otherwise invent some other way to ensure the new refresh token is correctly received at the client before revoking the old." These sorts of details will
by codebje 6y ago
"… or otherwise invent some other way to ensure the new refresh token is correctly received at the client before revoking the old."
These sorts of details will typically wind up in an implementation report document. It's rare that an IETF protocol specification document will attempt to pre-determine the solution to all such implementation details up front, and IMO, not good when they do.
In some contexts, it may be much better to require the application to re-obtain resource owner authorisation than to allow a replay of a refresh token. In others, it may be much better to avoid requiring resource owner authorisation. What you see as a bug, others would see as a critical feature.