← Back to Baseline

MB-R327

HUMAN VERIFICATION REQUIRED ASVS 10.4.15 Protect authorization details (when oauth_oidc is used)

MB-C18 ASVS Level 3 Human Assurance High

For a server-side client (which is not executed on the end-user device), the authorization server ensures that the 'authorization\_details' parameter value is from the client backend and that the user has not tampered with it. For example, by requiring the usage of pushed authorization request (PAR) or JWT-secured Authorization Request (JAR).