mattrglobal / oidc-portable-identities

oidc-portable-identities
https://mattrglobal.github.io/oidc-portable-identities/
3 stars 3 forks source link

Introduction - Needs rework #1

Open tplooker opened 3 years ago

tplooker commented 3 years ago

Technically in an id_token the sub is scoped to iss. This scoping protects user from impersonation by another IDP, portable identities need other solution for achieving this goal e.g by making the subject identifier cryptographically verifiable there are new opportunities to safely seperate out the relationship the End-User has to the provider.