Skip to content

Commit b9182cc

Browse files
authored
Added user education section back for clarity
1 parent a931238 commit b9182cc

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

draft-ietf-oauth-cross-device-security.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -567,6 +567,8 @@ It SHOULD be clear to the user how to decline the request. To avoid accidental a
567567

568568
If the user uses an application on a mobile device to scan a QR code, the application MAY display information advising the user under which conditions they should expect to be asked to scan a QR code and under which circumstances they should never scan a QR code (e.g. display a message that the QR code will only be displayed on kiosks within trusted locations or on trusted websites hosted on a specific domain, and never in e-mail or other media and locations).
569569

570+
The user experience MAY include information to further educate the user on cross-device consent phishing attacks and reinforce the conditions under which authorization grants may be requested.
571+
570572
**Limitations:** Improvements to user experience on their own is unlikely to be sufficient and SHOULD be used in conjunction with other controls described in this document.
571573

572574
### Authenticated flow

0 commit comments

Comments
 (0)