Skip to content

Conversation

kevinchalet
Copy link
Member

@kevinchalet kevinchalet commented Jun 9, 2025

This PR proactively implements the https://www.ietf.org/archive/id/draft-ietf-oauth-rfc7523bis-01.html#section-4 draft that addresses a vulnerability in the OIDC protocol.

Note: tier-6+ sponsors have been notified by email.

…d use the new "client-authentication+jwt" JSON Web Token type
@kevinchalet kevinchalet added this to the 7.0.0-preview4 milestone Jun 9, 2025
@kevinchalet kevinchalet self-assigned this Jun 9, 2025
@kevinchalet kevinchalet merged commit d95b322 into openiddict:dev Jun 9, 2025
6 checks passed
@kevinchalet kevinchalet deleted the client_assertions branch June 9, 2025 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant