Hi Arjun, Thanks for raising this and for linking the counterpart issue on our draft.
We have discussed issue #3 further: https://github.com/NiYuan224/draft-liu-oauth-cross-domain-txn-token/issues/3 I think we are aligned on applying the non-expansion principle from Transaction Tokens §13.15 to `tctx` transcription: `tctx` fields may be added, removed, or changed, provided that the resulting authorization is no broader than the input authorization. If you are willing, the positive/negative examples you mentioned and any concrete use cases would be very helpful for refining the AS/TTS processing rules. Thanks again, Yuan Hi George, Pieter, Sean, I opened an issue on the profile about claims transcription: §7 cov=rs sub, txn, scope, rctx and identity claims, but not tctx, so the claim c=ass carrying the authorized operation has no transcription rule while the =ne carrying request environment does. Two consequences — tctx may =e omitted entirely with §7.2/§9.5 still satisfied, and where it =s carried its values are unconstrained. The issue proposes a §7.5 and=notes the same question in draft-liu-oauth-cross-domain-txn-token, whose F=gure 4 example is a stock trade. https://git=ub.com/gffletch/tt_xdomain/issues/20<https://github.com/gffletch/tt_xdomain/issues/20> Counterpart on the other draft: https://github.com/NiYuan2=4/draft-liu-oauth-cross-domain-txn-token/issues/3<https://github.com/NiYuan224/=raft-liu-oauth-cross-domain-txn-token/issues/3> I have negative conformance vectors for these transitions and am happy t= contribute text or tests. Arjun Garg
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
