← Back to Baseline

MB-R245

HUMAN VERIFICATION REQUIRED ASVS 10.2.2 Mix-up attack defense (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If the OAuth client can interact with more than one authorization server, it has a defense against mix-up attacks. For example, it could require that the authorization server return the 'iss'parameter value and validate it in the authorization response and the token response.