openid / OpenID4VP

58 stars 20 forks source link

Remove the client_metadata_uri authorization parameter #210

Closed jogu closed 4 months ago

jogu commented 4 months ago

There are undocumented & unsolved security issues around client_metadata_uri (#14) and further concerns that it's not clear what client metadata parameters can actually be used in it (#17), and from the feedback we have received so far it seems no one is relying on it.

closes #202 closes #14