Can BPN validation be bypassed? #521
-
Describe the bugI would like to know if BPN validation can be bypassed if Catena-X portal does not check Connector URLs of onboarded connectors (need to admit, not being too deep into BPN details yet). Thus, how this risk is mitigated currently? Potential vector
Expected behaviorNot being able to negotiate a contract Possible Implementation to mitigate riskuse |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments
-
FYI I converted this to a discussion. Also, the BPN validation received a significant overhaul with the introduction of SSI and VerifiableCredentials in version |
Beta Was this translation helpful? Give feedback.
-
In the old release, someone would have to circumvent portal security and register a false connector. With release |
Beta Was this translation helpful? Give feedback.
-
@SebastianOpriel did the answers help? Were you already able to test it again? |
Beta Was this translation helpful? Give feedback.
FYI I converted this to a discussion. Also, the BPN validation received a significant overhaul with the introduction of SSI and VerifiableCredentials in version
0.5.x
.