OpenBanking-Brasil / specs-seguranca

Documentação das especificações do GT de Segurança do Open Banking Brasil. As especificações ainda estão em versão draft e não devem ser utilizadas para implementação.
67 stars 45 forks source link

Padronização de request_uri html/eng #386

Closed karinacabral closed 1 year ago

karinacabral commented 1 year ago

Adição das informações no item 5.2.2:

  1. shall ensure that, in case of sharing the Authorization Server for other services, in addition to Open Finance, it does not disclose and/or allow the use of non-certified methods in the Open Finance environment;
  2. shall ensure that the settings disclosed to other participants through OpenID Discovery (indicated by the Well-Known file registered in the Directory) are restricted to the operating modes to which the institution has certified;
    1. shall keep in your settings the methods for which there are still active clients;
    2. shall update the records that use non-certified methods, through bilateral treatment between the institutions involved.
  3. shall refuse requests, for the Open Finance environment, that are outside the modes of operation to which the institution has certified its Authorization Server;
  4. must refuse authentication requests that include an id_token_hint, as the id_token held by the requester may contain Personally Identifiable Information, which could be sent unencrypted by the public client.
  5. the minimum expiration time of request_uri must be 60 seconds.