Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lack of client identification in Solid-OIDC + WAC #22

Open
michielbdejong opened this issue Jan 23, 2025 · 0 comments
Open

Lack of client identification in Solid-OIDC + WAC #22

michielbdejong opened this issue Jan 23, 2025 · 0 comments

Comments

@michielbdejong
Copy link

When using Solid-OIDC to "log in" to a Solid app, that app gets all the same rights over your data that you yourself do.

This is fine if you're logging into a file browser tool but not if you're logging into a chess game.

I added this warning to the readme of Pivot but it also applies to other Solid servers that implement WAC.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant