-
assigned issue to
Dave Tonge
The current text has the requirement for the OP to include at_hash and auth_req_id in the ID Token. But there is no requirement for the Client to verify these values or an explanation of what to do is the values are invalid.