[Openid-specs-fapi] Issue #533: DPoP & resource leaks (openid/fapi)

josephheenan issues-reply at bitbucket.org
Wed Aug 3 14:34:19 UTC 2022


New issue 533: DPoP & resource leaks
https://bitbucket.org/openid/fapi/issues/533/dpop-resource-leaks

Joseph Heenan:

As per FAPI2 security analysis & Daniel’s presentation to the WG today:

‌

![](https://bitbucket.org/repo/K7gLBb/images/1918918523-Screenshot%202022-08-03%20at%2015.30.34.png)
We need to decide whether to mitigate this attack or simply document it and the possible mitigations.



More information about the Openid-specs-fapi mailing list