What is Nostr?
jared
npub1kun…wd3c
2025-01-17 16:31:02
in reply to nevent1q…k9ze

jared on Nostr: In any authentication scenarios that are claims based (SAML, OIDC/OAuth), it’s the ...

In any authentication scenarios that are claims based (SAML, OIDC/OAuth), it’s the responsibility of the app developers to select an immutable identifier claim but many developers will select email address (or a similar claim like upn) which relies on domain names that can be reused (thus not immutable).

So, this type of vulnerability likely exists in many apps regardless of the identity provider.

However, the problem here is that the identity provider doesn’t provide any consistent immutable identifiers for the app developers to have chosen.
Author Public Key
npub1kunwwx7wtpfqzxq6e6yny6hy9pqxems8zw2ln0cjkc4k95zynv3s4kwd3c