-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update draft-ietf-oauth-transaction-tokens.md #89
Conversation
Addresses text regarding the `aud` claim throughout the document. Issue oauth-wg#76
Although your changes sufficiently capture what is needed, what I liked about the previous draft is that it clearly identified that each Trust Domain MUST have a unique identifier, which is set as the |
Ok, let me see if there is a good place to add that. I wonder if it will be easier to merge PR #90 first and then let me fix this one as there may be conflicts? |
Makes sense to work on this after we merge #90
…On Fri, Apr 26, 2024 at 3:11 PM George Fletcher ***@***.***> wrote:
Ok, let me see if there is a good place to add that. I wonder if it will
be easier to merge PR #90
<#90> first and
then let me fix this one as there may be conflicts?
—
Reply to this email directly, view it on GitHub
<#89 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AB55UG77Y2GZKFE7FSVPC7LY7LGIFAVCNFSM6AAAAABFO22ZLKVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDAOBQGE3TSNZWGI>
.
You are receiving this because your review was requested.Message ID:
***@***.***>
|
@@ -339,7 +339,7 @@ JWT claims as well as defines new claims. These claims are described below: | |||
: REQUIRED A unique transaction identifier as defined in Section 2.2 of {{RFC8417}}. When used in the transaction token, it identifies the entire call chain. | |||
|
|||
`sub`: | |||
: REQUIRED A unique identifier for the subject as defined by the `aud` trust domain. Unlike OpenID Connect, the `sub` claim is NOT associated with the `iss` claim. | |||
: REQUIRED A unique identifier for the subject within the context of the `aud` trust boundary. Unlike OpenID Connect, the `sub` claim is NOT associated with the `iss` claim. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Did you intend for "trust boundary" to be something separaet from "trust domain"? I'd rather not invoke an additional concept if we can avoid it.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I agree. Let me fix that.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated
changed trust boundary to trust domain to not introduce a new term/concept
Addresses text regarding the
aud
claim throughout the document. Issue #76