You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Metadata elements such as client_name and logo_uri present in a clients metadata document are self attested by the client, pertain to the clients identity and often used to form UX (in obtaining user consent). They therefore create the possibility for client impersonation. A security consideration should be added to the document that discusses this and more generally any other metadata that may be open to abuse in this manner. In general the only part of the client's identity that can be validated by the AS in following this specification is the clients "client_uri".
The text was updated successfully, but these errors were encountered:
tplooker
changed the title
Certain metadata elements when self asserted by the client pose vectors for impersonation
Certain metadata elements pose vectors for impersonation
Nov 9, 2022
Metadata elements such as client_name and logo_uri present in a clients metadata document are self attested by the client, pertain to the clients identity and often used to form UX (in obtaining user consent). They therefore create the possibility for client impersonation. A security consideration should be added to the document that discusses this and more generally any other metadata that may be open to abuse in this manner. In general the only part of the client's identity that can be validated by the AS in following this specification is the clients "client_uri".
The text was updated successfully, but these errors were encountered: