Skip to content

Allowing JWT as tamper evident containers from PEP to PDP #248

@identitymonk

Description

@identitymonk

Subject data will be more than often extracted from OAuth2 JSON Web Token but by passing just the payload of it we are stripping the digital signature and the chain of custody on this information.

Supporting JWT can allow a longer term feature that would see Transaction Tokens [txn-tokens - https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/ ] to be passe as structure of context.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions