Challenge 3: How is IntendedUse bound to an Intermediary (in TS5 API calls)?
Basically same scenario as previous one, but here one of the registered usesIntermediary RPs over-asks credentials; either from services that end-RPs own run themselves, or from services run by one of the other registrered Intermediaries.
Since the IntendedUse class is not linked to any the specific Intermediaries, it appears to be no way for an end-relying party to stop such attack ?