Validation of dpop_jkt on PAR endpoint #1370
Closed
pey-lun-hsieh-gt
started this conversation in
Ideas
Replies: 1 comment 3 replies
-
dpop_jkt is validated at the PAR endpoint to match the DPoP Proof JWT's jwk thumbprint, what other kind of validation do you think is needed when only dpop_jkt is provided? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I realised that
dpop_jktparameter, while accepted on PAR, is not validated if provided on its own withoutDPoPheader? Is that intended and why?Because by the specs, one can provide either
dpop_jktparameter OR theDPoPheader. So if only the former is provided, we should validate the value early instead of leaving the validation to later at Token endpoint?Beta Was this translation helpful? Give feedback.
All reactions