You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Solid-OIDC relies on solid:oidcIssuer delegation in WebID Document, SAI, similarly, relies on interop:hasAuthorizationAgent. Compromising any of them can lead to gaining owner-level access to all storage owned by the agent WebID denotes.
After re-reading what you wrote above, are we saying the same thing: solid/solid-oidc#219 (comment) ? I mean the issuer origin. It is separate from the oidcIssuer value changing.
Let's separate those two cases. Here, I only focus on situations where the WebID Document is compromised and the triple with solid:oidcIssuer gets changed.
Solid-OIDC relies on
solid:oidcIssuer
delegation in WebID Document, SAI, similarly, relies oninterop:hasAuthorizationAgent
. Compromising any of them can lead to gaining owner-level access to all storage owned by the agent WebID denotes.Prior discussion
The text was updated successfully, but these errors were encountered: