Skip to content

Issuer check failures? #22

@kevinbaker

Description

@kevinbaker

Per 4.3 (Token Issuance - issuer checks) what if there are some failures?

  1. Multiple 1P cookies? And user is required to select between multiple accounts currently logged in at the Issuer side (for example, multiple @gmail.com accounts on a home PC).

  2. You note "cookies sent represent a logged in user, and if the logged in user " ...

  • What if the user's login is expired using the email address, but the Issuer wants to make sure a valid login is done before returning "email_verified": true? (also, desiring 2FA usage at the Issuer side.)

Is there any browser flow to redirect to an Issuer page to have the Issuer confirm login details before returning to the original page flow?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions