Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document threats where a Solid-OIDC issuer performs illegal activities #21

Open
csarven opened this issue Oct 13, 2024 · 1 comment
Open

Comments

@csarven
Copy link
Member

csarven commented Oct 13, 2024

The idea that a service could perform illegal activities was original raised in:

solid/webid-profile#118 (comment)

@elf-pavlik
Copy link
Member

elf-pavlik commented Oct 13, 2024

Could you please add a specific use case?

OIDC Issuer, as the Identity Provider, has the highest user trust since it can authenticate anything as the user, in contrast to apps with the lowest trust and can only do precisely what the user explicitly authorized them to do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants