As highlighted by Torsten, attributes like client_name and client_logo that are present in the clients metadata can be a source of possible impersonation if the AS places false trust in this information, the existing security consideration around impersonation should be expanded to highlight this.
As highlighted by Torsten, attributes like client_name and client_logo that are present in the clients metadata can be a source of possible impersonation if the AS places false trust in this information, the existing security consideration around impersonation should be expanded to highlight this.