(no title)
Ronnie76er | 5 years ago
https://openid.net/specs/openid-connect-core-1_0-final.html#...
It's likely (although like others have noted, this is scant on details), that this value was correct and represented the authenticated user.
A relying party should not use the email value to authenticate the user.
Not contesting that this is a bug that should be fixed and a potential security issue, but perhaps not as bad.
Anyone else? Am I reading this right?
unknown|5 years ago
[deleted]
m_herrlich|5 years ago
dwaite|5 years ago
cfors|5 years ago
dwaite|5 years ago
homakov|5 years ago