You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: Subject Identifiers for Security Event Tokens
143
-
PROTECTEDSERVERMETADATA:
143
+
OPRM:
144
144
author:
145
145
- ins: M.B. Jones
146
146
name: Michael B. Jones
@@ -562,18 +562,29 @@ TODO: consider adding a IANA Registry for metadata, similar to Section 7.1.1 of
562
562
{{RFC8414}}. This would allow other specs to add to the metadata.
563
563
564
564
### Authorization scheme {#authorization-scheme}
565
-
Authorization scheme used by the receiver to authorize with the Transmitter's management API for SET event stream.
565
+
SSF is an HTTP based signals sharing framework. It is agnostic to the authentication and authorization schems used to secure stream configuration APIs. It does not provide any SSF specific authentication and authorization schemes but relies on the cooperating parties mutual security considerations. Authorization scheme section of the metadata, providers disovery informaton related to the transmitter's stream management APIs.
566
566
567
567
type
568
568
569
-
> The authorization scheme. This specification defines the values "oauth", "oauth2", "oauthbearertoken" REQUIRED.
569
+
> The authorization scheme. This specification defines the values "oauth",
570
+
"oauth2", "oauthbearertoken" REQUIRED.
571
+
572
+
spec_uri
573
+
574
+
> An HTTP-addressable URL pointing to the authentication scheme's
575
+
specification. OPTIONAL.
576
+
577
+
documentation_uri
578
+
579
+
> An HTTP-addressable URL pointing to the authentication scheme's usage
580
+
documentation. OPTIONAL.
570
581
571
582
The receiver will call the transmitter APIs by providing appropriate credentials as mentioned in the type.
572
583
573
584
574
585
If the Authorization scheme is OAuth2
575
-
- The Transmitter SHOULD publish Protected Server Metadata {{PROTECTEDSERVERMETADATA}} to aid the discovery of metadata needed to interact with an OAuth 2.0 protected resource.
576
-
- Discovery of the Protected Server Metadata {{PROTECTEDSERVERMETADATA}} is outside the scope of this specification.
586
+
- The Transmitter SHOULD publish Protected Server Metadata {{OPRM}} to aid the discovery of metadata needed to interact with an OAuth 2.0 protected resource.
587
+
- Discovery of the Protected Server Metadata {{OPRM}} is outside the scope of this specification.
577
588
- The receiver may obtain an access token using the Client
578
589
Credential Grant {{CLIENTCRED}}, or any other method suitable for the Receiver and the
0 commit comments