Hi Arjun,

Thanks for raising this and for linking the counterpart issue on our draft.

We have discussed issue #3 further:
https://github.com/NiYuan224/draft-liu-oauth-cross-domain-txn-token/issues/3

I think we are aligned on applying the non-expansion principle from Transaction 
Tokens §13.15 to  `tctx` transcription:  `tctx` fields may be added, removed, 
or changed, provided that the resulting authorization is no broader than the 
input authorization.

If you are willing, the positive/negative examples you mentioned and any 
concrete use cases would be very helpful for refining the AS/TTS processing 
rules.

Thanks again,
Yuan




Hi George, Pieter, Sean,

I opened an issue on the profile about claims transcription: §7 cov=rs sub, 
txn, scope, rctx and identity claims, but not tctx, so the claim c=ass carrying 
the authorized operation has no transcription rule while the =ne carrying 
request environment does. Two consequences — tctx may =e omitted entirely with 
§7.2/§9.5 still satisfied, and where it =s carried its values are 
unconstrained. The issue proposes a §7.5 and=notes the same question in 
draft-liu-oauth-cross-domain-txn-token, whose F=gure 4 example is a stock trade.

https://git=ub.com/gffletch/tt_xdomain/issues/20<https://github.com/gffletch/tt_xdomain/issues/20>

Counterpart on the other draft: 
https://github.com/NiYuan2=4/draft-liu-oauth-cross-domain-txn-token/issues/3<https://github.com/NiYuan224/=raft-liu-oauth-cross-domain-txn-token/issues/3>

I have negative conformance vectors for these transitions and am happy t= 
contribute text or tests.

Arjun Garg
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to