You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TL;DR phishing WebIDs using different cases IRIs or characters that just look similar to human eye
As we work on workflows to request access, in cases where End-user (not a Client) requests access, authorization agent should check if that End-user exists in Resource Owner's address book and mark it clearly on the consent screen.
The text was updated successfully, but these errors were encountered:
elf-pavlik
changed the title
authorization agent should check user's address book if it includes Requestin Party
authorization agent should check Resource Owner's address book if it includes requesting End-user's WebID
Apr 10, 2021
Overall work is being tracked in #302, a planned approach that verification and creates agent registrations happens before any specific data is shared or access requested.
Based on conversation in solid/authentication-panel#161 (comment)
TL;DR phishing WebIDs using different cases IRIs or characters that just look similar to human eye
As we work on workflows to request access, in cases where End-user (not a Client) requests access, authorization agent should check if that End-user exists in Resource Owner's address book and mark it clearly on the consent screen.
The text was updated successfully, but these errors were encountered: