OAuth security BCP addition
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Quiet
- Domain
- authorization, security
Research direction
Start by reading the linked OAuth Security Topics Update draft and compare each mentioned attack with the current FAPI document. Check the existing private_key_jwt aud treatment, which the issue says is already addressed. Done means every relevant attack has a decided treatment and the document reflects it.
Written by the indexing model from the issue text.
Description
Originally submitted by josephheenan (Joseph Heenan) on 2026-03-16
Note that there's an update to the OAuth security in progress:
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics-update/
We should probably address the document and each mentioned attack in some way.
1 attack is the private_key_jwt aud issue that's already addressed. I'm not sure about the others.
Bitbucket status: new
Bitbucket origin: issue 855
- Dominant language
- HTML
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
-
component: Implementation & Deployment Advice
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
Similar issues
-
cosh prompt_scanner_hook.py crashes with AttributeError on a non-object JSON payload (every sibling hook guards this)Possibly taken @zjncs claimed this today. Opencomponent:cosh
Difficulty 1/5 Under an hour Newbie friendliness 92/100
agentic-os-org/ANOLISA#6114 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Uuriko/project-room#1523 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Gentleman-Programming/gentle-ai#5280 ·
Maintainers usually reply within 1 day
-
The shim's mount reader runs awk in the caller's locale, so its answer can differ from the sh reader'sPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
FluidNumerics/fluid-walk-blocker#162 ·
Maintainers usually reply within 1 day
-
fix(security): dependency-pinning misses list-item run steps and npm options before installPossibly taken @MohammedAlkindi claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day