Basic - 7.5. Assertion Substitution

Issue #142 resolved
hideki nara created an issue

I think that * OP must check client_id and redirect_url to return assertions to proper RP. * RP is recommended to use state or/and UA session cookie to bind returned assertions to proper authz request.

Comments (4)

  1. Log in to comment