Skip to content

Commit 7f5b8cf

Browse files
Add sentence suggesting that Issuer information should be validated by the Receiver (#174)
* Add sentence suggesting that Issuer information should be validated by the Receiver * Update openid-sharedsignals-framework-1_0.md Co-authored-by: Tim Cappalli <[email protected]> --------- Co-authored-by: Tim Cappalli <[email protected]>
1 parent 86eb59c commit 7f5b8cf

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

openid-sharedsignals-framework-1_0.md

+2-1
Original file line numberDiff line numberDiff line change
@@ -605,7 +605,8 @@ Transmitter.
605605
## Obtaining Transmitter Configuration Metadata
606606

607607
Using the Issuer URL as documented by the Transmitter, the Transmitter Configuration
608-
Metadata can be retrieved.
608+
Metadata can be retrieved. Receivers SHOULD ensure that the Issuer URL comes from a
609+
trusted source and uses the `https` scheme.
609610

610611
Transmitters supporting Discovery MUST make a JSON document available at the
611612
path formed by inserting the string "/.well-known/ssf-configuration" into the

0 commit comments

Comments
 (0)