← Back to Baseline

MB-R262

HUMAN VERIFICATION REQUIRED ASVS 10.6.2 Logout DoS protection (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

The OpenID Provider mitigates denial of service through forced logout. By obtaining explicit confirmation from the end-user or, if present, validating parameters in the logout request (initiated by the relying party), such as the 'id\_token\_hint'.