The referer setting in the Enterprise generateToken service does not seem to create a token that is valid only to the define URL. The generated token will still work on maps or scripts on different web hosts that I tested so far.
Is this a bug or did I misunderstand the referer's usage listed in the documentation?
https://developers.arcgis.com/rest/users-groups-and-items/generate-token.htm
Allen
It's bug. Bug ID: BUG-000141502. https://support.esri.com/en-us/bug/generated-token-to-a-federated-arcgis-server-with-an-in-bug-00014...