Skip to content

define sessiontranscript for mdoc profile over DC API #135

@jogu

Description

@jogu
          From a security perspective, what kind of attacks are mitigated by inclusion of the clientID in the sessiontranscript?

Inclusion of the clientId also has other issues, like which value is used if there are multiple signatures, or if the wallet ignores RP authentication.

Originally posted by @martijnharing in #122 (comment)

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions