ietf-wg-gnap / gnap-core-protocol

141 stars 26 forks source link

Checks needed to defeat user collaborative attacks are unfortunately out of the scope of the document #290

Closed Denisthemalice closed 2 years ago

Denisthemalice commented 3 years ago

On page 11, in step (7) the text states:

“the RS determines if the token is sufficient for the request by examining the token. The means of the RS determining this access are out of scope of this specification”.

This means that checks that would be able to defeat a user collaborative attack are out of the scope of the document. The controls able to defeat such an attack mandate the presence of one or more attributes chosen by the client into an access token.

If such attributes cannot be incorporated into an access token, the inability to defeat user collaborative attacks should be advertised in the security considerations section.