Skip to content

No RFC 2119 Language in "Threats and Vulnerabilities" Section#35

Merged
selfissued merged 1 commit into
oauth-wg:mainfrom
hannestschofenig:patch-1
Mar 2, 2026
Merged

No RFC 2119 Language in "Threats and Vulnerabilities" Section#35
selfissued merged 1 commit into
oauth-wg:mainfrom
hannestschofenig:patch-1

Conversation

@hannestschofenig

Copy link
Copy Markdown
Contributor

It makes no sense to use RFC 2119 language (MUST) in the threats section. The mitigation section is the right place to do so.

It makes no sense to use RFC 2119 language (MUST) in the threats section. The mitigation section is the right place to do so.

@selfissued selfissued left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm going to replace the deleted text with:

If the JWT could be used in an application context in which it could be
confused with other kinds of JWTs,
then mitigations can be employed to prevent these substitution attacks.

@selfissued
selfissued merged commit 4029a30 into oauth-wg:main Mar 2, 2026
1 check passed
selfissued added a commit that referenced this pull request Mar 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants