Hi all, I would like to ask a couple of questions regarding draft-gco-oauth-delegate-sd-jwt to better understand its design.
Unlike the classic Token Exchange pattern where the AS validates the actor's identity and the delegation relationship, this draft enables Holders and Delegate Holders to directly determine downstream entities without AS intervention. Since this chain requires the RS to trust each hop's decision, I am wondering if this shift might introduce new security risks. Meanwhile, I noticed that the working group currently has several other individual drafts addressing multi-step delegation (A delegates to B, B delegates to C) from various angles, some of them being: 1. draft-liu-oauth-chain-delegation defines a delegation_chain claim, capturing hop-specific constraints and optionally carrying cryptographic confirmation from each delegator. 2. draft-li-oauth-delegated-authorization defines a token-chain framework where clients locally issue subordinate tokens. 3. draft-niyikiza-oauth-attenuating-agent-tokens defines Attenuating Authorization Tokens (AATs) for task-scoped offline delegation. Given that multiple drafts are exploring this space, I would love to learn if there is any plan to first clarify the core use cases and harmonize these delegation models to ensure a consolidated baseline. I would highly appreciate any thoughts from the authors and the working group on these aspects. Best Regards, Yuan
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
