-
-
Notifications
You must be signed in to change notification settings - Fork 60
Closed
Labels
Description
Spec: https://openid.net/specs/openid-financial-api-part-2-1_0.html
Work Required
- Based on Financial-grade API Security Profile 1.0 - Part 1: Baseline #246
- Support JARM (with setting to require it)
- Support PAR
- Add configuration that restricts the client to more safe settings
- Check
s_hashin ID token (based onstate) - Require signed request object
- More restictive mTLS settings: TLS considerations
- No
nonealgorithm - No
RSASSA-PKCS1-v1_5algorithms likeRS256 -
jwks_urirequire HTTPS - No JWE
x5u/jku - Unique
kidfor JWK Sets (consideralg/use/ktyandcrv)
- Check
📌 This issue is here to track interest for the implementation. Leave a 👍 if you would like this implemented.
SuperPauly