diff --git a/index.html b/index.html index 77b3a39..3c957fd 100644 --- a/index.html +++ b/index.html @@ -781,6 +781,20 @@
This section is non-normative.
+ +The Protected Properties requirement is intended to prevent agents other than the WebID owner from modifying specific properties, notably solid:oidcIssuer. When a Solid server does not enforce these protections, the WebID Profile is open to attack:
solid:oidcIssuer, redirecting Solid-OIDC authentication to an attacker-controlled OpenID Provider and impersonating the WebID owner.