openid / openid/fapi

CIBA - Make clear limitation of binding message

Open
#597 5 comments 0 reactions 1 assignee View on GitHub

@davidgtonge is already working on this.

Since Jul 11, 2026.

component: CIBA migrated-from-bitbucket priority: major type: bug
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by dgtonge (Dave Tonge) on 2023-06-21

As raised by Pedram and Tim - there are still attacks possible even when a binding message is used (with an attacker controlled client). We should add this to the security considerations.


Bitbucket status: open

Bitbucket origin: issue 609

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.