[demo] A possible mitigation to session fixation - OID4VCI

18 March 2026

Here is raised the hypothesis:

A direct post response is both a grant and a code that give access to further presentations / issuance, always prepend with an authentication