3 ms·
Thank you just for reading it! I've opened an issue on the project at https://github.com/billpg/CrossRequestTokenExchange/issues/6 https://github.com/billpg/Cro
by billpg 3y ago
Thank you just for reading it! I've opened an issue on the project at https://github.com/billpg/CrossRequestTokenExchange/issues/6 https://github.com/billpg/CrossRequestTokenExchange/issues/6
If I may rewrite your scenario to check I understand it...
An attacker sets themselves up as an Initiator and registers https://evil.example/TimeOut/ https://evil.example/TimeOut/ as their URL to receive the TokenIssue POST requests. The attacker then makes a TokenCall request to which the Issuer responds by making the TokenIssue POST request to the malicious "time out" endpoint. As this never responds, that initial connection is kept open.
- buzer 3y agoYes, though as the "time out" endpoint does not respond, both the initial connection and the connection to "time out" endpoint are kept open.
- billpg 3y agoThank you, I think that's worth addressing in the questions section and I might have an idea on resolving the issue.
- billpg 3y agoIn case you're still reading this, I've updated this document to version 2, answering your comment directly and adding an alternative immediate response instead of keeping the connection open. As this is still a public draft and not an established standard, I hope discussion will bring a consensus that one way of responding is better and a future draft will only specify that way.