Skip to content

Commit 9c6ef4d

Browse files
c2boadeinega
andauthored
Apply suggestions from andrii's review
Co-authored-by: Andrii Deinega <[email protected]>
1 parent 3be60e6 commit 9c6ef4d

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

draft-ietf-oauth-status-list.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -997,7 +997,7 @@ This behaviour may be mitigated by:
997997

998998
An Issuer could maliciously or accidentally bypass the privacy benefits of the herd privacy by either:
999999
- Generating a unique Status List for every Referenced Token. By these means, the Issuer could maintain a mapping between Referenced Tokens and Status Lists and thus track the usage of Referenced Tokens by utilizing this mapping for the incoming requests.
1000-
- Encoding a unique uri in each Reference Token which points to the underlying Status List. This may involve using uri components such as query parameters, unique path segments or fragments to make the uri unique.
1000+
- Encoding a unique URI in each Reference Token which points to the underlying Status List. This may involve using URI components such as query parameters, unique path segments, or fragments to make the URI unique.
10011001

10021002
This malicious behaviour can be detected by Relying Parties that request large amounts of Referenced Tokens by comparing the number of different Status Lists and their sizes with the volume of Reference Tokens being verified.
10031003

0 commit comments

Comments
 (0)