(ed) A number should be assigned to the last sentence in FAPI Part 2, 5.2.3

Issue #210 resolved
Takahiko Kawasaki created an issue

FAPI Implementer's Draft version 2, Part 2, 5.2.3. has the following sentence at the bottom.

To verify that the authorization response was not tampered using ID Token as the detached signature, the client shall verify that s_hash value is equal to the value calculated from the state value in the authorization response in addition to all the requirements in 3.3.2.12 of [OIDC].

A number should be assigned to this sentence. To be concrete, this sentence should be listed as the 10th clause in the section.

Comments (4)

  1. Log in to comment