Re: [OAUTH-WG] WGLC for Browser-based Apps

2023-08-11 Thread Dick Hardt
I have a different interpretation of the objective of using a service worker, and it aligns with descriptions in most of those links -- minimize the risk of the access token and refresh token exfiltration from the application by malicious JS code. Service workers, when implemented properly,

Re: [OAUTH-WG] Call for adoption - SD-JWT-based Verifiable Credentials

2023-08-11 Thread Oliver Terbu
Thank you very much! We greatly appreciate your insightful feedback and continuous support. As we move forward, we are fully committed to diligently refining the document to meet the rigorous technical standards upheld by the IETF working group. Best regards, Oliver & Daniel (authors) On Fri,

Re: [OAUTH-WG] Call for adoption - Attestation-Based Client Authentication

2023-08-11 Thread Rifaat Shekh-Yusef
All, Based on the responses to this call for adoption, we declare the *Attestation-Based Client Authentication* draft adopted as a WG document. Authors, Feel free to submit a WG document at your convenience. Regards, Rifaat & Hannes On Tue, Aug 8, 2023 at 11:51 AM Paul Bastian wrote: >

Re: [OAUTH-WG] Call for adoption - SD-JWT-based Verifiable Credentials

2023-08-11 Thread Rifaat Shekh-Yusef
All, Based on the responses to this call for adoption, we declare the *SD-JWT-based Verifiable Credentials* draft adopted as a WG document. Authors, Feel free to submit a WG document at your convenience. Regards, Rifaat & Hannes On Tue, Aug 8, 2023 at 11:51 AM Paul Bastian wrote: > I