Skip to content

Security: Consider limiting the URLs that are considered valid #232

@scouten-adobe

Description

@scouten-adobe

There is currently no stated restriction or guidance on the URIs used for verifiedIdentities[?].uri or verifiedIdentities[?].provider.id as specified in §8.1.2.5, "Verified identities, though we assume that those would be https URIs.

Consider restricting these URIs to https or a known-approved list of URI types.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions