OpenID4VP icon indicating copy to clipboard operation
OpenID4VP copied to clipboard

Privacy considerations on request_uri

Open paulbastian opened this issue 1 year ago • 2 comments

In the current state, according to RFC9101, the Wallet must fetch the Request Object from request_uri without having any means to verify the identity and authenticity of the Verifier. The request for this object therefore may leak data to the Verifier without the User knowing that or giving consent.

Is this something that should be stated in a privacy consideration section?

paulbastian avatar Jan 14 '24 20:01 paulbastian