JARM Downgrade
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 3
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Originally submitted by Yaron Zehavi (Yaron Zehavi) on 2025-06-01
The JARM spec doesn’t specify how a Relying Party should handle a situation where it’s request of JARM response is ignored by the OpenID Provider, for example by returning instead of the expected JWT response, the code + state + iss query parameters.
Such a scenario may be viewed as a downgrade of a security mechanism, which RP should identify and potentially also reject. Perhaps rejection should be only in case OP explicitly published its JARM support using response_modes_supported
Bitbucket status: open
Bitbucket origin: issue 745
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the JARM specification and the issue's eight comments, focusing on the ignored JARM response scenario and the role of response_modes_supported. Determine whether the specification should define downgrade detection or rejection, and document the agreed behavior and conditions as done.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100