openid / openid/fapi

JARM Downgrade

Open
#733 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component: Implementation & Deployment Advice migrated-from-bitbucket priority: major type: proposal
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by Yaron Zehavi (Yaron Zehavi) on 2025-06-01

The JARM spec doesn’t specify how a Relying Party should handle a situation where it’s request of JARM response is ignored by the OpenID Provider, for example by returning instead of the expected JWT response, the code + state + iss query parameters.

 

Such a scenario may be viewed as a downgrade of a security mechanism, which RP should identify and potentially also reject. Perhaps rejection should be only in case OP explicitly published its JARM support using response_modes_supported


Bitbucket status: open

Bitbucket origin: issue 745

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the JARM specification and the issue's eight comments, focusing on the ignored JARM response scenario and the role of response_modes_supported. Determine whether the specification should define downgrade detection or rejection, and document the agreed behavior and conditions as done.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.