Hi all,

I would like to ask a couple of questions regarding 
draft-gco-oauth-delegate-sd-jwt to better understand its design.

Unlike the classic Token Exchange pattern where the AS validates the actor's 
identity and the delegation relationship, this draft enables Holders and 
Delegate Holders to directly determine downstream entities without AS 
intervention. Since this chain requires the RS to trust each hop's decision, I 
am wondering if this shift might introduce new security risks.

Meanwhile, I noticed that the working group currently has several other 
individual drafts addressing multi-step delegation (A delegates to B, B 
delegates to C) from various angles, some of them being:

  1.  draft-liu-oauth-chain-delegation defines a delegation_chain claim, 
capturing hop-specific constraints and optionally carrying cryptographic 
confirmation from each delegator.
  2.  draft-li-oauth-delegated-authorization defines a token-chain framework 
where clients locally issue subordinate tokens.
  3.  draft-niyikiza-oauth-attenuating-agent-tokens defines Attenuating 
Authorization Tokens (AATs) for task-scoped offline delegation.

Given that multiple drafts are exploring this space, I would love to learn if 
there is any plan to first clarify the core use cases and harmonize these 
delegation models to ensure a consolidated baseline.

I would highly appreciate any thoughts from the authors and the working group 
on these aspects.

Best Regards,
Yuan
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to