[Openid-specs-fapi] Issue #210: A number should be assigned to the last sentence in FAPI Part 2, 5.2.3 (openid/fapi)

Takahiko Kawasaki issues-reply at bitbucket.org
Fri Jan 18 02:28:08 UTC 2019


New issue 210: A number should be assigned to the last sentence in FAPI Part 2, 5.2.3
https://bitbucket.org/openid/fapi/issues/210/a-number-should-be-assigned-to-the-last

Takahiko Kawasaki:

FAPI Implementer's Draft version 2, Part 2, 5.2.3. has the following sentence at the bottom.

> To verify that the authorization response was not tampered using ID Token as the detached signature, the client shall verify that s_hash value is equal to the value calculated from the state value in the authorization response in addition to all the requirements in 3.3.2.12 of [OIDC].

A number should be assigned to this sentence. To be concrete, this sentence should be listed as the 10th clause in the section.




More information about the Openid-specs-fapi mailing list