Skip to content

Conversation

@pull
Copy link

@pull pull bot commented Nov 29, 2025

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

wbamberg and others added 3 commits November 28, 2025 20:15
* Draft a federated identity guide

* Update files/en-us/web/security/authentication/federated_identity/index.md

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update files/en-us/web/security/authentication/federated_identity/index.md

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* back-channel logout example sentence

* OP->IdP

* Clearer language

* ...

* ...

* Clarify authorization code injection

* Reword client id preamble

* Update CSRF description

* Add a section on FedCM

* Link to BCP

* Mention PKCE downgrade attacks

* Recommend client auth based on public-key crypto

* Add sections on choosing idps and a summary

* Update wording for client secret

* clarify that PKCE is not used when the attacks work

* Apply suggestions from code review

Co-authored-by: Hamish Willee <hamishwillee@gmail.com>

* Hint that client===RP

* Review feedback

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hamish Willee <hamishwillee@gmail.com>
Add 'json' as a value for sec-fetch-dest
* New 'Defenses' page

* Move top-level pages under 'Defenses'

* Update sidebar

* Fix wiki history

* Fix a link

* Apply suggestions from code review

Co-authored-by: Chris Mills <chrisdavidmills@gmail.com>

* Fix review comments

---------

Co-authored-by: Chris Mills <chrisdavidmills@gmail.com>
@pull pull bot locked and limited conversation to collaborators Nov 29, 2025
@pull pull bot added the ⤵️ pull label Nov 29, 2025
@pull pull bot merged commit 3907089 into All-Blockchains:main Nov 29, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants