OpenBanking-Brasil / specs-seguranca

Documentação das especificações do GT de Segurança do Open Banking Brasil. As especificações ainda estão em versão draft e não devem ser utilizadas para implementação.
68 stars 45 forks source link

CIBA spec: Exception for CIBA on id_token_hint #407

Open marcusalmgren opened 1 year ago

marcusalmgren commented 1 year ago

The document https://github.com/OpenBanking-Brasil/specs-seguranca/blob/main/open-banking-brasil-financial-api-1_ID3.md says that the Authorization server "must refuse authentication requests that include an id_token_hint", and that clause should perhaps be rephrased to exclude the CIBA backchannel request to avoid possible conflicting statements.

guilhermedecampo commented 1 year ago

That’s correct, this phrase conflicts with 5.2.2.1, it's reasonable to remove the item 21 from the 5.2.2.