KantaraInitiative / wg-uma

This is the repository of all specifications related to the User Managed Access Group
http://kantarainitiative.org/confluence/display/uma/
Other
27 stars 21 forks source link

Security considerations could be made clearer #342

Closed mrpotes closed 6 years ago

mrpotes commented 6 years ago

We had a discussion about section 5.2 in our team, and two people had come to different understandings about what the attack is. It would be nice if each security considerations section each described the attack before or after the more abstract description of it.

For example,

Requesting Party Bob using malicious Client controlled by malicious Requesting Party Carlos: Bob does XYZ, Client gives RPT to Carlos.

ciseng commented 6 years ago

+1