JARM Downgrade
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Domain
- authentication, security
Research direction
Start by reading the JARM specification and the issue's eight comments, focusing on the ignored JARM response scenario and the role of response_modes_supported. Determine whether the specification should define downgrade detection or rejection, and document the agreed behavior and conditions as done.
Written by the indexing model from the issue text.
Description
Originally submitted by Yaron Zehavi (Yaron Zehavi) on 2025-06-01
The JARM spec doesn’t specify how a Relying Party should handle a situation where it’s request of JARM response is ignored by the OpenID Provider, for example by returning instead of the expected JWT response, the code + state + iss query parameters.
Such a scenario may be viewed as a downgrade of a security mechanism, which RP should identify and potentially also reject. Perhaps rejection should be only in case OP explicitly published its JARM support using response_modes_supported
Bitbucket status: open
Bitbucket origin: issue 745
- Dominant language
- HTML
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
component: Implementation & Deployment Advice
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
detecting inconsistent .well-known/openid-configuration vs .well-known/oauth-authorization-server on conformance testsPossibly taken @jogu claimed this 8 days ago. Opencomponent: Certification component: FAPI2: Advanced Authorization component: Implementation & Deployment Advice
Difficulty 5/5 Over a week Newbie friendliness 35/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
NousResearch/hermes-agent#131271 · 1 comment ·
Maintainers usually reply within 1 day
-
failed-test failure:ai-fixable failure:insufficient-data failure:test-needs-update scout-playwright Team:Entity Analytics
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
elastic/kibana#294939 · 2 comments ·
Maintainers usually reply within 1 day
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
area: backend enhancement priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
snapotter-hq/SnapOtter#1879 ·
Maintainers usually reply within 1 day
-
area/dependencies backport/26.4 kind/cve severity/high source/scan-dependencies status/triage
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 2 days