Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(incomplete) mention PoP token issuer for app origin
Creating this as a placeholder, it's still incomplete in several aspects: * we should mention somewhere why PoP token issuer is better than Origin header (namely because of solid/web-access-control-spec#34) * we should mention that a PoP token is only valid if the issuer is listed in the id token's audiences (is this something the IDP checks and then signs for? I don't even know)
- Loading branch information