Skip to content

Limit options supported for the format and resolution method for image based assets in credential issuer metadata #185

@tplooker

Description

@tplooker

Currently in places like the credential issuer logo as merged in openid/OpenID4VCI#170. The logo is permitted to be a URI which can being either a network resolvable reference like an https based URL or a data based URI. Furthermore it can be an image of a variety of formats such as an svg, png and or JPEG. Collectively these options represent a significant interoperability issue for implementations and a potential security issue due to the surface area of general purpose URI schemes like data URI's which have capability well beyond image encoding, such as allowing for encoding javascript which opens a potential risk around RCE.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions