Skip to content

Conversation

@ThisIsMissEm
Copy link
Contributor

@ThisIsMissEm ThisIsMissEm commented Mar 30, 2025

@ThisIsMissEm ThisIsMissEm force-pushed the feat/rework-for-client-id-prefix branch from 4b09863 to 52cffcc Compare March 30, 2025 14:38
@ThisIsMissEm
Copy link
Contributor Author

@aaronpk you'll probably want to look at the rendered version of this when comparing.

The client metadata document MAY also be served with more specific content types
as long as the response is JSON and conforms to `application/<AS-defined>+json`.

All URLs contained within the Client ID Metadata Document must be absolute and

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From an implementation standpoint, it is quite convenient to allow data: URLs.

Indeed, this allows the AS to serve UI without the need to proxy client defined assets (logo, privacy policy, ToS, etc.).

I mean it's fine if you want to leave data: as not recommended, but I would not put it in the same basket as javascript: that should probably be out right forbidden.

@ThisIsMissEm
Copy link
Contributor Author

Have marked this as a draft given the status of Client ID Prefixes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants