OpenID4VP
OpenID4VP copied to clipboard
Mandate JAR-encoded Request Objects
It should be discussed to mandate the JAR-encoded Authorization Request according to RFC9101 and restrict usage of URL- encoded Authorization Request from RFC6749 as
- they do not offer integrity
- they do not offer authenticity
Restricting the URL-encoded pattern could result in a significant security improvement.