Skip to content

Commit 8e42829

Browse files
obfuscoderKai Lehmann
authored andcommitted
Remove note on IdP to validate nonce (#582) (#583)
Co-authored-by: Kai Lehmann <kai.lehmann@1und1.de>
1 parent 7eac182 commit 8e42829

File tree

1 file changed

+0
-2
lines changed

1 file changed

+0
-2
lines changed

spec/index.bs

-2
Original file line numberDiff line numberDiff line change
@@ -2047,8 +2047,6 @@ the <a http-header>Origin</a> header value is represented by the
20472047
[=IDP=]-specific, the [=user agent=] cannot perform this check.
20482048
</div>
20492049

2050-
Note: An [=IDP=] should validate the nonce, if present, to prevent CSRF-style attacks.
2051-
20522050
The response body must be a JSON object that can be [=converted to an IDL value|converted=] to an {{IdentityProviderToken}} without an exception.
20532051

20542052
Every {{IdentityProviderToken}} is expected to have members with the following semantics:

0 commit comments

Comments
 (0)