You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TODO The spec does not distinguish between replay (attacker forwards code to other wallet/end-user) and stealing the code (attacker scans code intended for other user). This needs to be fixed.
Imported from AB/Connect bitbucket: https://bitbucket.org/openid/connect/issues/1838
Original Reporter: KristinaYasuda
From the security analysis: openid / connect / Pull Request #468: First draft of OpenID 4 VC Security Analysis — Bitbucket cc @danielfett
The text was updated successfully, but these errors were encountered: