Closed tlodderstedt closed 2 years ago
The Security BCP is going to recommend the iss response parameter as mix-up defense.
https://github.com/oauthstuff/draft-ietf-oauth-security-topics/pull/19/files
I think we should consider to add this parameter to OAuth 2.1.
At the interim meeting it was discussed to revisit this topic once the iss draft reaches RFC status.
iss
At IETF 113 it was agreed to fold in guidance on using the iss parameter by including an example in the spec and referencing RFC 9207 for the full details.
minutes
The Security BCP is going to recommend the iss response parameter as mix-up defense.
https://github.com/oauthstuff/draft-ietf-oauth-security-topics/pull/19/files
I think we should consider to add this parameter to OAuth 2.1.