Charles Eckel has entered the following ballot position for draft-ietf-oauth-rfc8725bis-09: No Objection
When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Thanks to Valery Smyslov for the ARTART review and to the authors for addressing the points raised. ## Comments ### Section 3.11, RECOMMENDED vs REQUIRED use of "typ" 681 Explicit typing is RECOMMENDED for new uses of JWTs, because without 682 it, mutually exclusive validation rules are harder to enforce and 683 cross-JWT confusion becomes more likely. Is there a specific reason the "typ" requirement is "RECOMMENDED" rather than "REQUIRED" for new uses of JWTs? _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
