Thank you Charles for your review!
Opened https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65
Best,
Yaron
------ Original Message ------
From "Charles Eckel via Datatracker" <[email protected]>
To "The IESG" <[email protected]>
Cc [email protected]; [email protected];
[email protected]; [email protected]
Date 13/08/2026 21:06:44
Subject Charles Eckel's No Objection on draft-ietf-oauth-rfc8725bis-09:
(with COMMENT)
Charles Eckel has entered the following ballot position for
draft-ietf-oauth-rfc8725bis-09: No Objection
When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)
Please refer to
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.
The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/
----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------
Thanks to Valery Smyslov for the ARTART review and to the authors for
addressing the points raised.
## Comments
### Section 3.11, RECOMMENDED vs REQUIRED use of "typ"
681 Explicit typing is RECOMMENDED for new uses of JWTs, because without
682 it, mutually exclusive validation rules are harder to enforce and
683 cross-JWT confusion becomes more likely.
Is there a specific reason the "typ" requirement is "RECOMMENDED" rather than
"REQUIRED" for new uses of JWTs?
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]