Skip to content

Commit 10794f7

Browse files
obfuscoderKai Lehmann
and
Kai Lehmann
authored
Remove note on IdP to validate nonce (w3c-fedid#582) (w3c-fedid#583)
Co-authored-by: Kai Lehmann <kai.lehmann@1und1.de>
1 parent 82db3af commit 10794f7

File tree

1 file changed

+0
-2
lines changed

1 file changed

+0
-2
lines changed

spec/index.bs

-2
Original file line numberDiff line numberDiff line change
@@ -2045,8 +2045,6 @@ the <a http-header>Origin</a> header value is represented by the
20452045
[=IDP=]-specific, the [=user agent=] cannot perform this check.
20462046
</div>
20472047

2048-
Note: An [=IDP=] should validate the nonce, if present, to prevent CSRF-style attacks.
2049-
20502048
The response body must be a JSON object that can be [=converted to an IDL value|converted=] to an {{IdentityProviderToken}} without an exception.
20512049

20522050
Every {{IdentityProviderToken}} is expected to have members with the following semantics:

0 commit comments

Comments
 (0)