Skip to content

a session on the RP with the same key #258

Description

@adeinega

Section "Federated sessions" states that

If the key is correct, the user agent will create a session on the RP with the same key as the SP.

What should happen when this key is provided by the SP (1) but it's incorrect (2)? The spec doesn't describe this, implying that the user agent will create a new session on the RP.

However, isn't this an indication the user's device was compromised?

My understanding that the SP has no reason to pass some junk as key's value, it does it only when it has a valid DBSC session, right?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions