openid-certification / oidctest

THE CERTIFICATION TEST SUITE HAS BEEN MIGRATED TO A NEW SERVICE https://www.certificatinon.openid.net
Other
49 stars 15 forks source link

OP-BackChannel-RpInitLogout-modified-idtoken_hint #156

Closed panva closed 5 years ago

panva commented 5 years ago

Status: 🆗 but 💡

The test description reads

Uses RP initiated logout to end a Session at the OP. The request has post_logout_redirect_uri and an incorrect id_token_hint

It should read something along the lines 'Sent id_token_hint is stripped of its signature and has modified "alg" header'

Similar treatment to the description should be made for OP-BackChannel-RpInitLogout-wrong-idtoken_hint

rohe commented 5 years ago

Updated