Events without label "editorial"
Issues
------
* oauth-wg/oauth-transaction-tokens (+0/-3/💬4)
3 issues received 4 new comments:
- #357 §14.6 Scope Processing: behavior undefined when subject_token has no
`scope` claim (2 by PieterKas, tulshi)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/357
- #351 Using RFC 9396's authorization_details as a claim and for request_context (1 by PieterKas)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/351
- #349 More rctx/tctx fun (1 by dteleguin)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/349 [WGLC Feedback]
3 issues closed:
- More rctx/tctx fun https://github.com/oauth-wg/oauth-transaction-tokens/issues/349 [WGLC Feedback]
- §14.6 Scope Processing: behavior undefined when subject_token has no `scope` claim https://github.com/oauth-wg/oauth-transaction-tokens/issues/357
- ... req_wl ... https://github.com/oauth-wg/oauth-transaction-tokens/issues/331 [WGLC Feedback]
* oauth-wg/oauth-sd-jwt-vc (+0/-1/💬1)
1 issues received 1 new comments:
- #414 what does "Type Metadata MAY be retrieved" mean? (1 by bc-pi)
https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/414
1 issues closed:
- what does "Type Metadata MAY be retrieved" mean? https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/414
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+3/-9/💬4)
3 issues created:
- Allow for alternative key-bound JWT formats (by arndt-s)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/212
- Key-bound refresh tokens are limited to the key lifetime (by arndt-s)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/211
- Client ID == assertion subject restriction (by arndt-s)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/210
3 issues received 4 new comments:
- #202 Interims Feedback by Denis (2 by paulbastian)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/202
- #170 Client metadata ? (1 by tplooker)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/170 [discuss] [ready-for-pr]
- #164 In section 10.6. (Replay Attack Detection) the current description is incorrect (1 by paulbastian)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/164
9 issues closed:
- Interims Feedback: AS/RS metadata to signal demand for client attestation https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/195 [ready-for-pr]
- Draft9 - Clarification on DPoP with "attest_jwt_client_auth" + HAIPv1 https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/198 [ready-for-pr]
- Interims Feedback by Denis https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/202
- Further attest_jwt_client_auth client instance bindings https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/114 [discuss] [has-pr]
- Authorization code binding to client instance https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/56 [discuss] [has-pr]
- Interims Feedback by Denis https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/202
- In section 10.6. (Replay Attack Detection) the current description is incorrect https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/164
- A client should be able to request a challenge without using a challenge endpoint https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/163
- Allow other PoP mechanisms to be used https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/204
* oauth-wg/draft-ietf-oauth-rfc8725bis (+5/-0/💬0)
5 issues created:
- ARTART: §3.11 SET example — normative SHOULD vs descriptive should (by
yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/46 [artart review]
- ARTART: Clarify PBES2 p2c rejection threshold in §3.13 (by yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/45 [artart review]
- ARTART: §3.11 pairing omission — SHOULD vs MAY? (by yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/44 [artart review]
- ARTART: Split long explicit-typing sentence in §3.11 (by yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/43 [artart review]
- ARTART: Add conditions for when SHOULDs may be ignored (§§3.1, 3.2, 3.6, 3.10, 3.11) (by yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/42 [artart review]
* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+3/-0/💬12)
3 issues created:
- Security Consideration: discourage clients from using dynamic CIMD documents
(by itsvs)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/89
- Requiring ASes to return the `iss` parameter for mix-up prevention (by itsvs)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/88
- Add `token_endpoint_auth_methods_supported` to client metadata (by aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/87 [ietf-126]
3 issues received 12 new comments:
- #89 Security Consideration: discourage clients from using dynamic CIMD
documents (3 by ThisIsMissEm, aaronpk)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/89
- #88 Requiring ASes to return the `iss` parameter for mix-up prevention (6 by ThisIsMissEm, aaronpk, itsvs)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/88
- #87 Add `token_endpoint_auth_methods_supported` to client metadata (3 by aaronpk, panva)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/87 [ietf-126]
Pull requests
-------------
* oauth-wg/oauth-identity-chaining (+5/-0/💬3)
5 pull requests submitted:
- (by bc-pi)
- (by bc-pi)
- (by PieterKas)
- (by PieterKas)
- (by PieterKas)
2 pull requests received 3 new comments:
- #201 a little more fixing up of the examples (2 by PieterKas, bc-pi)
https://github.com/oauth-wg/oauth-identity-chaining/pull/201
- #199 Replace inline code formatting with backticks (1 by PieterKas)
https://github.com/oauth-wg/oauth-identity-chaining/pull/199
* oauth-wg/oauth-transaction-tokens (+2/-0/💬0)
2 pull requests submitted:
- (by tulshi)
- (by PieterKas)
* oauth-wg/oauth-sd-jwt-vc (+1/-0/💬0)
1 pull requests submitted:
- (by bc-pi)
* oauth-wg/oauth-v2-1 (+0/-0/💬1)
1 pull requests received 1 new comments:
- #250 Make `iss` response parameter required to be sent by the AS (1 by
will-bartlett)
https://github.com/oauth-wg/oauth-v2-1/pull/250
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+2/-0/💬1)
2 pull requests submitted:
- (by c2bo)
- (by paulbastian)
1 pull requests received 1 new comments:
- #186 Adds an example generation script (1 by paulbastian)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/pull/186
Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps
* https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document
--
To have a summary like this sent to your list, see:
https://github.com/ietf-github-services/activity-summary
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]