In the sessions, during the item "Offline workload access for user-owned 
resources without refresh tokens", I mentioned there's a cross-domain 
transaction token proposal. Sending the relevant draft to the list:

https://datatracker.ietf.org/doc/draft-liu-oauth-cross-domain-txn-token/

The draft introduces two patterns to solve cross-domain transaction tokens:
*           Mode A (Txn-Token I -> JAG -> Access Token -> Txn-Token II): 
Combines standard Identity Chaining with standard Transaction Tokens to pass 
workflow-related claims via JAGs and access tokens.
*           Mode B (Txn-Token I -> JAG -> Txn-Token II): An optimized flow 
allowing a downstream TTS to directly accept a JAG, reducing cross-domain 
round-trips for access tokens.

OAuth working group is busy working on the use cases, so no solutions will be 
discussed this ietf, but this might be a relevant proposal to begin with. 
CC-ing them as well.

Best,
Peter

Attachment: oauth_REFUa6_vHzfu-NlNe5ssDs7JPyA.eml
Description: oauth_REFUa6_vHzfu-NlNe5ssDs7JPyA.eml

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to