Dears,
Thank you for considering the risks these flows present, as part of your 
"Updates to OAuth 2.0 Security Best Current Practice" 
draft<https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-update-03.html#name-shared-consent-in-brokered->.

I have special interest in this topic since we operate a platform offering 
brokered redirect-based OAuth.
In our case we solved it with internal contracts, providing an app_id inside 
login_hint, telling the upstream AS who the downstream client is.
However, our solution does not offer internet-scale interoperability.

But the proposed solutions in the draft fall also short in my view:

  *   Registering downstream clients at upstream authorization servers defeats 
the purpose of brokered OAuth flows.
  *   Presenting users with consent screens from brokers adds friction and does 
not empower upstream AS to take informed decisions.

I believe an improved pattern could be an OAuth Authorization Request 
Delegation Chain:
A request-time RAR object that conveys clear information about downstream 
clients and brokers, in a verifiable and tamper-resistant way:
https://datatracker.ietf.org/doc/draft-zehavi-oauth-authz-req-del-chain/

The proposed solution doesn't include any new endpoints, AS metadata, grant 
types, error codes, token formats etc.
Only an informative recommended RAR type with prescribed creation and 
validation processing rules.

I'm aware of parallel work on the topic of actor delegation, relevant among 
others in AI and OBO use-case.
As my proposal is aimed at request time, I believe it complements actor 
delegation work and does not compete with it.

I welcome WG feedback on the proposal, especially:

  *   Can it help solve the identified security issue?
  *   Are further alignment and layering required with regards to actor 
delegation prior art?

Regards,
Yaron ZEHAVI

This message and any attachment ("the Message") are confidential. If you have 
received the Message in error, please notify the sender immediately and delete 
the Message from your system, any use of the Message is forbidden. 
Correspondence via e-mail is primarily for information purposes. RBI neither 
makes nor accepts legally binding statements via e-mail unless explicitly 
agreed otherwise. Information pursuant to ยง 14 Austrian Companies Code: 
Raiffeisen Bank International AG; Registered Office: Am Stadtpark 9, 1030 
Vienna, Austria; Company Register Number: FN 122119m at the Commercial Court of 
Vienna (Handelsgericht Wien).

Classification: GENERAL
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to