← Back to Baseline

MB-R258

HUMAN VERIFICATION REQUIRED ASVS 10.5.3 Issuer metadata validation (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

The client rejects attempts by a malicious authorization server to impersonate another authorization server through authorization server metadata. The client must reject authorization server metadata if the issuer URL in the authorization server metadata does not exactly match the pre-configured issuer URL expected by the client.