Charles Eckel has entered the following ballot position for
draft-ietf-oauth-rfc8725bis-09: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to 
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks to Valery Smyslov for the ARTART review and to the authors for
addressing the points raised.

## Comments

### Section 3.11, RECOMMENDED vs REQUIRED use of "typ"

681        Explicit typing is RECOMMENDED for new uses of JWTs, because without
682        it, mutually exclusive validation rules are harder to enforce and
683        cross-JWT confusion becomes more likely.

Is there a specific reason the "typ" requirement is "RECOMMENDED" rather than
"REQUIRED" for new uses of JWTs?



_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to