Skip to content

Security considerations around both "bad" icon URIs and "bad" names #151

@xmlgrrl

Description

@xmlgrrl

RSR Sec 4 talks about how "A malicious resource server could register a bad icon URI at an authorization server, "infecting" the authorization server either when the icon is retrieved or by confusing a human resource owner about the nature of the resource set being protected." However, the same is true for a scope or resource set name, not just an icon_uri. This should be mentioned as well.

Metadata

Metadata

Assignees

No one assigned

    Labels

    V1.0.1rsrc-regRelated to resource registration (or the original UMA1 resource reg spec)

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions