Scope states "stated attacker model" without explicitly referencing it

Issue #641 resolved
Nat Sakimura created an issue

Currently, it goes:

Scope

This specification is a general purpose high security profile of OAuth 2.0 that has been proved by formal analysis to meet the stated attacker model. This document specifies the requirements for:

It is not clear what what is the stated attacker model. It should be explicit.

Proposes:

Replace “the stated attacker model” with “FAPI 2.0 - Part 1: Attacker model”

Comments (2)

  1. Log in to comment