Originally submitted by josephheenan (Joseph Heenan) on 2020-11-19
FAPI 2 Baseline says the AS:
- shall support rich authorization requests according to [I-D.ietf-oauth-rar]
I’m not sure I understand the reasoning here. It seems unnecessary for servers to support RAR if scopes or OIDC claims are sufficient for their use cases? (I can understanding the reasons for point people towards RAR if scopes/etc aren’t sufficient for their use case.)
Bitbucket status: resolved
Bitbucket origin: issue 346
FAPI 2 Baseline says the AS:
I’m not sure I understand the reasoning here. It seems unnecessary for servers to support RAR if scopes or OIDC claims are sufficient for their use cases? (I can understanding the reasons for point people towards RAR if scopes/etc aren’t sufficient for their use case.)
Bitbucket status: resolved
Bitbucket origin: issue 346