Events without label "editorial"
Issues
------
* oauth-wg/oauth-browser-based-apps (+0/-2/💬2)
2 issues received 2 new comments:
- #111 Terminology concern: “Backend for Frontend (BFF)” (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/111
- #105 Clarification on refresh token requirements for browser-based clients (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/105
2 issues closed:
- Terminology concern: “Backend for Frontend (BFF)” https://github.com/oauth-wg/oauth-browser-based-apps/issues/111
- Clarification on refresh token requirements for browser-based clients https://github.com/oauth-wg/oauth-browser-based-apps/issues/105
* oauth-wg/oauth-transaction-tokens (+0/-0/💬1)
1 issues received 1 new comments:
- #357 §14.6 Scope Processing: behavior undefined when subject_token has no
`scope` claim (1 by Dhruvagnihotri)
https://github.com/oauth-wg/oauth-transaction-tokens/issues/357
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+1/-0/💬8)
1 issues created:
- RS metadata registration is incomplete (by c2bo)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/213
2 issues received 8 new comments:
- #211 Key-bound refresh tokens are limited to the key lifetime (5 by
EthanHeilman, arndt-s)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/211
- #210 Client ID == assertion subject restriction (3 by arndt-s, tplooker)
https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/210
* oauth-wg/oauth-identity-assertion-authz-grant (+2/-0/💬2)
2 issues created:
- Standardize error code for "user does not have a license" - today we get
`invalid_grant` (by pcarleton)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/111
- Usage of "resource" request parameter incompatible with oauth-identity-chaining (by randomstuff)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/110
2 issues received 2 new comments:
- #111 Standardize error code for "user does not have a license" - today we
get `invalid_grant` (1 by mcguinness)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/111
- #110 Usage of "resource" request parameter incompatible with oauth-identity-chaining (1 by mcguinness)
https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/110
* oauth-wg/draft-ietf-oauth-rfc8725bis (+0/-5/💬2)
1 issues received 2 new comments:
- #45 ARTART: Clarify PBES2 p2c rejection threshold in §3.13 (2 by yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/45 [artart review]
5 issues closed:
- ARTART: Add conditions for when SHOULDs may be ignored (§§3.1, 3.2, 3.6, 3.10, 3.11) https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/42 [artart review]
- ARTART: §3.11 SET example — normative SHOULD vs descriptive should https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/46 [artart review]
- ARTART: §3.11 pairing omission — SHOULD vs MAY? https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/44 [artart review]
- ARTART: Split long explicit-typing sentence in §3.11 https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/43 [artart review]
- ARTART: Clarify PBES2 p2c rejection threshold in §3.13 https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/45 [artart review]
* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+0/-0/💬1)
1 issues received 1 new comments:
- #89 Security Consideration: discourage clients from using dynamic CIMD
documents (1 by itsvs)
https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/89
Pull requests
-------------
* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+1/-0/💬0)
1 pull requests submitted:
- (by tplooker)
* oauth-wg/draft-ietf-oauth-rfc8725bis (+3/-0/💬1)
3 pull requests submitted:
- (by yaronf)
- (by yaronf)
- (by yaronf)
1 pull requests received 1 new comments:
- #48 ARTART: clarify PBES2 p2c rejection threshold (Section 3.13) (1 by
yaronf)
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/48
Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps
* https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document
--
To have a summary like this sent to your list, see:
https://github.com/ietf-github-services/activity-summary
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]