You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are undocumented & unsolved security issues around client_metadata_uri ( #14 ) and further concerns that it's not clear what client metadata parameters can actually be used in it ( #17 ).
There's a further suggestion to decide an alternative way of fetching client metadata from a .well-known location ( #82 ).
Given all this I would like to propose we just remove client_metadata_uri from the specification entirely.
peppelinux, bc-pi, David-Chadwick and jruizaranguren