[Openid-specs-ab] Issue #1668: Security consideration (10.3. Fetching Presentation Definitions by Reference) has a MUST (openid/connect)

Nat issues-reply at bitbucket.org
Mon Oct 10 07:52:57 UTC 2022


New issue 1668: Security consideration (10.3. Fetching Presentation Definitions by Reference) has a MUST
https://bitbucket.org/openid/connect/issues/1668/security-consideration-103-fetching

Nat Sakimura:

A MUST should be stated in the main text and not in the security considerations. 

The current text states: 

> The protocol for the presentation\_definition\_uri MUST be https.

in subclause 10.3, which is in the Security Considerations. 

Proposal: 

Move the text containing MUST to subclause 5.2.


More information about the Openid-specs-ab mailing list