Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certain metadata elements pose vectors for impersonation #17

Open
tplooker opened this issue Nov 9, 2022 · 0 comments
Open

Certain metadata elements pose vectors for impersonation #17

tplooker opened this issue Nov 9, 2022 · 0 comments

Comments

@tplooker
Copy link
Member

tplooker commented Nov 9, 2022

Metadata elements such as client_name and logo_uri present in a clients metadata document are self attested by the client, pertain to the clients identity and often used to form UX (in obtaining user consent). They therefore create the possibility for client impersonation. A security consideration should be added to the document that discusses this and more generally any other metadata that may be open to abuse in this manner. In general the only part of the client's identity that can be validated by the AS in following this specification is the clients "client_uri".

@tplooker tplooker changed the title Certain metadata elements when self asserted by the client pose vectors for impersonation Certain metadata elements pose vectors for impersonation Nov 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant