Skip to content

Conversation

@Sakurann
Copy link
Collaborator

@Sakurann Sakurann commented Sep 29, 2023

problem statement, and various options that have been considered are explained in Issue #72.

There are use-cases when Credential Issuer is using different authorization servers depending on the grant type (for example, using existing AS for authz code grant and a new one for pre-auth because was not able to make changes to an existing AS in production.) Inspired by a newly adopted resource metadata draft in oauth wg https://datatracker.ietf.org/doc/html/draft-ietf-oauth-resource-metadata-00#section-2-2.4.

When discussed at oauth security workshop 2023, there have been no concerns with the approach, given that credential issuer needs how to differentiate from which AS each access token is coming from.

Co-authored-by: Giuseppe De Marco <giuseppe.demarco@teamdigitale.governo.it>
Co-authored-by: Christian Bormann <8774236+c2bo@users.noreply.github.com>
@Sakurann Sakurann requested a review from c2bo October 31, 2023 19:09
Names of sets or lists of things should be plural.
Co-authored-by: Giuseppe De Marco <demarcog83@gmail.com>
Co-authored-by: Joseph Heenan <joseph@heenan.me.uk>
@Sakurann Sakurann requested a review from pmhsfelix November 2, 2023 15:16
@Sakurann
Copy link
Collaborator Author

Sakurann commented Nov 2, 2023

agreed to merge following @pmhsfelix 's review

Copy link
Contributor

@pmhsfelix pmhsfelix left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved with just one comment.

@Sakurann Sakurann merged commit 5ec81b6 into main Nov 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants