4 ms·
That is a really bad specification with no examples, no formalization, and zero references. However, all server-side attack scenarios listed there are not poss
by machete143 9y ago
That is a really bad specification with no examples, no formalization, and zero references.
However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authentication, which is why we have OpenID Connect.
- homakov 9y agoNo, ignore the spec (it's just a list of traits i'd like to suggest), design issues are outlined after it.