openid / openid/fapi

Certification Team Query: error messages shown by OPs

Open
#434 6 comments 0 reactions 1 assignee View on GitHub

@davidgtonge is already working on this.

Since Jul 11, 2026.

component: Implementation & Deployment Advice migrated-from-bitbucket priority: major type: bug
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by Joseph Heenan (Joseph Heenan) on 2021-08-11

The certification team would appreciate any guidance from the working group on acceptable error messages when we’re reviewing certification submissions.

For example, we have a test:

This test uses an unregistered redirect uri. The authorization server should display an error saying the redirect uri is invalid, a screenshot of which should be uploaded

A large number of submissions we get the error message does not meet that criteria, I believe on the grounds it was viewed as ‘too technical’ to show to end users.

For FAPI submissions we’ve always adopted a position where error messages must at least “not be factually incorrect”. So for example “A problem occurred on our service, try again" is regarded as factually incorrect, but “Something went wrong.” is (just) regarded as okay.

We’re seeing “Something when wrong, please try again” commonly recently and aren’t sure whether to accept that.


Bitbucket status: open

Bitbucket origin: issue 434

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.