Issues
- 4
split from 2.2.1 - disallow account lockout
#2134 opened by elarlang - 2
V1 - cleanup from implementation requirements
#2137 opened by elarlang - 15
clarification for V4.1 and V4.2
#2139 opened by elarlang - 6
V4.1.3 - split principle and verifiable parts
#2196 opened by elarlang - 8
update 3.5.5
#2204 opened by elarlang - 2
review V51.3.3 and V51.3.4
#2181 opened by elarlang - 3
review V51.4.2
#2182 opened by elarlang - 0
clarify V5.3 and V5.5 section titles
#2206 opened by elarlang - 12
Compression based side-channel attacks and BREACH
#2203 opened by randomstuff - 20
V51 OAuth: discuss verification of the user consent
#2120 opened by randomstuff - 10
3.5.4 - token time-window validation
#2185 opened by elarlang - 2
3.3.5 - Update to correspond updated 3.3.2
#2172 opened by ryarmst - 3
V4 principles coverage
#2195 opened by elarlang - 7
3.5.3 update (stateless token signature or mac)
#2184 opened by elarlang - 21
V3 Terminology Addition
#2100 opened by ryarmst - 1
- 32
- 14
Add requirement about segmentation of SSO identities
#2150 opened by randomstuff - 20
2.10.4 and 6.4.1 seem like duplicates
#2130 opened by tghosth - 9
OAuth, Add Requirement about protection against modification of the RAR authorization_details parameter
#2151 opened by randomstuff - 3
V51 - OAuth - DPoP proof replay attack protection
#2188 opened by randomstuff - 10
14.2.1 - component up to date
#2164 opened by elarlang - 8
V14.2.7 - move to V10
#2167 opened by elarlang - 30
51.2.15 - OAuth - ask to be transaction-specific
#2092 opened by elarlang - 28
V51 - OAuth - sender-contrained refresh tokens
#2110 opened by elarlang - 0
review V51.4.3
#2183 opened by elarlang - 9
- 2
proposal: merge 14.2.4 and 14.2.5 and move to V1.10
#2165 opened by elarlang - 0
Clarify scope for chapter V10
#2173 opened by tghosth - 7
- 7
v3.2.1 identifier rotating for a stateless mechanism
#2112 opened by tghosth - 15
- 14
- 5
- 4
14.3.3 - reword for clarifying the goal
#2142 opened by elarlang - 4
Is 1.4.4 a useful and verifiable requirement.
#2147 opened by tghosth - 4
Consider Adding RASP for Runtime Attack Prevention
#2144 opened by ImanSharaf - 3
4.1.1 belongs in V4.2
#2143 opened by EnigmaRosa - 3
- 6
- 6
V1.11.3 and V11.1.6 - merge tactou requirements
#2138 opened by elarlang - 13
- 12
- 12
V51 revokation for OAuth tokens
#2111 opened by elarlang - 13
Deduplicate SSRF requirements
#2115 opened by tghosth - 9
- 7
V51 - OAuth - confidential client
#2109 opened by elarlang - 1
- 5
5.1.2 mass assignment is not really Input Validation
#2114 opened by tghosth - 0
Add DTLS certificate / SDP fingerprint attribute verification to WebRTC chapter (53.2)
#2098 opened by sandrogauci