-
-
Notifications
You must be signed in to change notification settings - Fork 60
Closed
Labels
Description
Spec: https://openid.net/specs/openid-financial-api-part-1-1_0.html
Work Required
- Support mTLS (>= 1.2)
- Add configuration that restricts the client to more safe settings
- Require
nonceorstatedepending onopenidscope - Public Client: require PKCE
- Store
redirect_uriin session and compare on redirect back - Require CSRF
- Compare scopes (no additional ones compared to requested scopes)
- Confidential Client: RSA >= 2048, EC >= 160, Symmetric Key >= 128
- No params in query, only request body / request jwt
- Set
Dateheader on requests - Set
x-fapi-interaction-idheader - Put
x-fapi-interaction-idvalue into telemetry events - Set
x-fapi-customer-ip-addressheader - Set
x-fapi-auth-dateheader
- Require
📌 This issue is here to track interest for the implementation. Leave a 👍 if you would like this implemented.
maennchen and SuperPauly