Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

3.6.1 "Subscriber" is not defined #1053

Closed
ike opened this issue Sep 13, 2021 · 2 comments
Closed

3.6.1 "Subscriber" is not defined #1053

ike opened this issue Sep 13, 2021 · 2 comments

Comments

@ike
Copy link
Collaborator

ike commented Sep 13, 2021

Hi there! This is my first issue, and I am new to application security as well as standards development in general. I have been a software developer for over ten years, mostly in web development. I have always had an interest in secure coding, but six months ago I started working as an AppSec Champion in my organization. I appreciate the work here tremendously! I have already used the ASVS to create checklists for our organization.

I would appreciate any critical feedback on how to be useful to the work here

I think that 3.6.1 could be updated to more clearly state the requirement. Does "subscriber" refer to the end user, or the RP? I realize that since I don't work on Federated CSPs this may be standard language that I am just unfamiliar with.

3.6.1 - Verify that relying parties specify the maximum authentication time to Credential Service Providers (CSPs) and that CSPs re-authenticate the subscriber if they haven't used a session within that period.

I would be happy to submit a PR with some updated language if that's helpful.

Thanks,
Isaac Lewis

@jmanico
Copy link
Member

jmanico commented Sep 13, 2021

Thanks for joining us! I think the "subscriber" is the end user here. New language would be helpful, go for it!

@jmanico
Copy link
Member

jmanico commented Sep 23, 2021

Its merged! :)

@jmanico jmanico closed this as completed Sep 23, 2021
elarlang pushed a commit to elarlang/ASVS that referenced this issue Oct 25, 2021
elarlang pushed a commit to elarlang/ASVS that referenced this issue Oct 25, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants