[Openid-specs-ab] Issue #1761: client_metadata_uri security considerations (openid/connect)

Kristina Yasuda issues-reply at bitbucket.org
Thu Dec 29 20:37:47 UTC 2022


New issue 1761: client_metadata_uri security considerations
https://bitbucket.org/openid/connect/issues/1761/client_metadata_uri-security

Kristina Yasuda:

Raised by George: “should we have some “security considerations” about following unknown URIs? For example, is there a requirement that the domain of the client\_id be the same as the domain of the client\_metadata\_uri?” \([original issue comment](https://bitbucket.org/openid/connect/pull-requests/354#comment-352038211)\)



More information about the Openid-specs-ab mailing list