So, RP is not in charge of validating the origin with given RPID in case of the response is coming from the native application? Instead, the platform validates associated domain and calling application?
Do I understand it correctly?
Topic:
Privacy & Security
SubTopic:
General
Tags: