I am reaaaaaallllly irritated by OIDC. ANd my websearch-foo is letting me down.
So when a client does the whole OIDC dance, everything is secure and safe.
But ...
How do I make sure when I want others to set up OIDC on my service that the OIDC-provider actually is trustworthy for a certain email-domain?
How do I make sure that the user doesn't just configure a fake OP for a domain that then harvests all the logins and passwords?
What did I miss?



