Events without label "editorial"
Issues
------
* oauth-wg/oauth-transaction-tokens (+0/-0/π¬2)
2 issues received 2 new comments:
- #357 Β§14.6 Scope Processing: behavior undefined when subject_token has no
`scope` claim (1 by Dhruvagnihotri)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/357
- #351 Using RFC 9396's authorization_details as a claim and for request_context (1 by sdatspun2)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/351
* oauth-wg/oauth-sd-jwt-vc (+1/-7/π¬11)
1 issues created:
- SD-JWT is not only a superset of JWT (by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/417
6 issues received 11 new comments:
- #417 SD-JWT is not only a superset of JWT (6 by adeinega, awoie, bc-pi)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/417
- #413 Editorial: clarify how path processing relates to claim metadata (1 by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/413
- #412 Editorial: move vct#integrity definition from 5.3.1 to 5.3 (1 by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/412
- #411 Define behaviour when wallet needs to resolve/process type metadata (1 by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/411
- #410 Define behaviour when the wallet needs to process the path (1 by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/410
- #409 Define behaviour for the wallet if `sd` in claims metadata does not correspond to `_sd` and Disclosures (1 by awoie)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/409
7 issues closed:
- Define behaviour for the wallet if `sd` in claims metadata does not correspond to `_sd` and Disclosures https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/409
- Define behaviour when the wallet needs to process the path https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/410
- Define behaviour when wallet needs to resolve/process type metadata https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/411
- Editorial: move vct#integrity definition from 5.3.1 to 5.3 https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/412
- Editorial: clarify how path processing relates to claim metadata https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/413
- SD-JWT is not only a superset of JWT https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/417
- Define behaviour of the wallet when claims metadata is malformed https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/408
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+1/-3/π¬1)
1 issues created:
- Allow other PoP mechanisms to be used (by c2bo)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/204
1 issues received 1 new comments:
- #200 Draft 9 - Relationship with rfc7521 (1 by c2bo)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/200
3 issues closed:
- Interim Feedback: Add more explanation/requirements on Client Attester https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/196 [ready-for-pr]
- Further implementer guidance on Client Instance Attestations https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/107 [pending-close] [discuss]
- Draft9 - Clarification on DPoP Combined Mode and `dpop_jkt` https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/199 [ready-for-pr]
* oauth-wg/oauth-identity-assertion-authz-grant (+0/-0/π¬2)
1 issues received 2 new comments:
- #73 Proposal: Workload/Agent Identity SSO and Explicit Delegated
βOn-Behalf-Ofβ Access (2 by kennethsinder, mcguinness)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/73
* oauth-wg/oauth-first-party-apps (+1/-5/π¬3)
1 issues created:
- add `redirect_uri` as a parameter (by aaronpk)
https://github.com/oauth-wg/oauth-first-party-apps/issues/179
2 issues received 3 new comments:
- #177 Differentiate actual errors from insufficient authorization by Status
Code (2 by aaronpk)
https://github.com/oauth-wg/oauth-first-party-apps/issues/177
- #134 Collect things that would need to happen to use the PAR endpoint (1 by aaronpk)
https://github.com/oauth-wg/oauth-first-party-apps/issues/134
5 issues closed:
- auth_session binds to a client instance, not a client? https://github.com/oauth-wg/oauth-first-party-apps/issues/175
- Collect things that would need to happen to use the PAR endpoint https://github.com/oauth-wg/oauth-first-party-apps/issues/134
- example is missing request 'response_type' parameter https://github.com/oauth-wg/oauth-first-party-apps/issues/172
- auth_session reuse https://github.com/oauth-wg/oauth-first-party-apps/issues/174
- possible mixup attack https://github.com/oauth-wg/oauth-first-party-apps/issues/176
* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+2/-2/π¬2)
2 issues created:
- Disallow the root path `/` as a CIMD URL (by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/86 [ietf-126]
- Be more prescriptive about how the AS should return errors (by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/85
2 issues received 2 new comments:
- #85 Be more prescriptive about how the AS should return errors (1 by
ThisIsMissEm)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/85
- #82 Add guidance for pattern-based Client ID Metadata Document URL admission policies (1 by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/82
2 issues closed:
- Review from Justin Richer https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/79
- Are SSRF checks when AS is running on loopback needed for URLs *within* CIMDs? https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/73
Pull requests
-------------
* oauth-wg/oauth-transaction-tokens (+3/-0/π¬1)
3 pull requests submitted:
- (by tulshi)
- (by PieterKas)
- (by PieterKas)
1 pull requests received 1 new comments:
- #360 Clarified req_wl value (1 by PieterKas)
https://github.com/oauth-wg/oauth-transaction-tokens/pull/360
* oauth-wg/oauth-sd-jwt-vc (+0/-0/π¬1)
1 pull requests received 1 new comments:
- #416 Fixes #408, #409, #410, #411, #412, #413, #417 (1 by danielfett)
https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/416
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+3/-0/π¬2)
3 pull requests submitted:
- (by c2bo)
- (by c2bo)
- (by c2bo)
2 pull requests received 2 new comments:
- #186 Adds an example generation script (1 by c2bo)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/pull/186
- #149 OAuth 2 artefact binding (1 by c2bo)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/pull/149
* oauth-wg/oauth-identity-assertion-authz-grant (+0/-0/π¬1)
1 pull requests received 1 new comments:
- #108 Add guidance on RAS-specific and private claims in the ID-JAG (1 by
aaronpk)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/pull/108
* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+1/-0/π¬3)
1 pull requests submitted:
- (by aaronpk)
3 pull requests received 3 new comments:
- #84 incorporate feedback from Justin Richer's review (1 by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/pull/84
- #63 require sending Accept header when fetching metadata (1 by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/pull/63 [ietf-126]
- #50 Restrict URI properties to absolute URIs using the https: scheme (1 by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/pull/50
Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps
* https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document
--
To have a summary like this sent to your list, see:
https://github.com/ietf-github-services/activity-summary
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]