You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
Learn more.
We use optional third-party analytics cookies to understand how you use GitHub.com so we can build better products.
You can always update your selection by clicking Cookie Preferences at the bottom of the page.
For more information, see our Privacy Statement.
Essential cookies
We use essential cookies to perform essential website functions, e.g. they're used to log you in.
Learn more
Always active
Analytics cookies
We use analytics cookies to understand how you use our websites so we can make them better, e.g. they're used to gather information about the pages you visit and how many clicks you need to accomplish a task.
Learn more
Impact
Issues
nonealgorithm was allowed in all flows.oic.consumer.Consumer.parse_authzreturns an unverified IdToken. The verification of the token was left to the discretion of the implementator.iatclaim was not checked for sanity (i.e. it could be in the future)Patches
nonealgorithm is now allowed only if using theresponse_typecodeiatclaim is now checked for sanity.References