← Back to Baseline

MB-R232

HUMAN VERIFICATION REQUIRED ASVS 6.8.1 IdP namespace isolation (when federated_identity is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If the application supports multiple identity providers (IdPs), the user's identity cannot be spoofed via another supported identity provider (eg. by using the same user identifier). The standard mitigation would be for the application to register and identify the user using a combination of the IdP ID (serving as a namespace) and the user's ID in the IdP.