Skip to content

Conversation

@elf-pavlik
Copy link
Member

@elf-pavlik elf-pavlik commented Jun 27, 2024

This is intended as a conversation starter. If we want to have proper client constraints, for example, acp:client, we need reliable global identifiers for clients. DynReg could be useful during early development, but production systems must always use URIs to denote clients. This way, the redirect_uri gets verified.

related:

@elf-pavlik elf-pavlik requested a review from acoburn June 27, 2024 19:07
@elf-pavlik elf-pavlik self-assigned this Jun 27, 2024
@michielbdejong
Copy link

I think (hope) we can still make client-side web apps work securely though, if we resume work on solid/webid-oidc-spec#34

@michielbdejong
Copy link

By client-side web apps I mean the "client" is the code running in a specific tab in a specific window of a specific browser on a specific device, even if its source code has a global identifier. Similar for smartphone apps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants