It says
10.4.8 Verify that refresh tokens have an absolute expiration, including if sliding refresh token expiration is applied.
(Source) OWASP ASVS 5.0 https://github.com/OWASP/ASVS/tree/v5.0.0#latest-stable-version---500
This is contrary to FAPI 2.0 Security Profile 5.3.2.1-9 that states "shall not use refresh token rotation except in extraordinary circumstances"
It says
(Source) OWASP ASVS 5.0 https://github.com/OWASP/ASVS/tree/v5.0.0#latest-stable-version---500
This is contrary to FAPI 2.0 Security Profile 5.3.2.1-9 that states "shall not use refresh token rotation except in extraordinary circumstances"