Skip to content

Commit 3be60e6

Browse files
c2bopaulbastian
andauthored
Apply suggestions from Paul's review
Co-authored-by: Paul Bastian <[email protected]>
1 parent e71650b commit 3be60e6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

draft-ietf-oauth-status-list.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -995,7 +995,7 @@ This behaviour may be mitigated by:
995995

996996
## Issuer Tracking of Reference Tokens
997997

998-
A malicious Issuer could bypass the privacy benefits of the herd privacy by
998+
An Issuer could maliciously or accidentally bypass the privacy benefits of the herd privacy by either:
999999
- Generating a unique Status List for every Referenced Token. By these means, the Issuer could maintain a mapping between Referenced Tokens and Status Lists and thus track the usage of Referenced Tokens by utilizing this mapping for the incoming requests.
10001000
- Encoding a unique uri in each Reference Token which points to the underlying Status List. This may involve using uri components such as query parameters, unique path segments or fragments to make the uri unique.
10011001

0 commit comments

Comments
 (0)