Skip to content

Remove client_metadata_uri authorization parameter #202

@jogu

Description

@jogu

There are undocumented & unsolved security issues around client_metadata_uri ( #14 ) and further concerns that it's not clear what client metadata parameters can actually be used in it ( #17 ).

There's a further suggestion to decide an alternative way of fetching client metadata from a .well-known location ( #82 ).

Given all this I would like to propose we just remove client_metadata_uri from the specification entirely.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions