Skip to content

Commit d418a5a

Browse files
authored
incorporated feedback from Mike Jones and Mike Leczcz (#130)
1 parent becb1fb commit d418a5a

File tree

1 file changed

+48
-5
lines changed

1 file changed

+48
-5
lines changed

openid-sharedsignals-framework-1_0.md

Lines changed: 48 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@ normative:
111111
date: November 2020
112112
target: https://www.rfc-editor.org/info/rfc8935
113113
title: Push-Based SET Token Delivery Using HTTP
114-
IDTOKEN:
114+
OpenID.Core:
115115
author:
116116
- ins: N. Sakimura
117117
name: Nat Sakimura
@@ -123,7 +123,7 @@ normative:
123123
name: Breno de Medeiros
124124
- ins: C. Mortimore
125125
name: Chuck Mortimore
126-
date: April 2017
126+
date: November 2014
127127
target: http://openid.net/specs/openid-connect-core-1_0.html#IDToken
128128
title: OpenID Connect Core 1.0 - ID Token
129129
OASIS.saml-core-2.0-os:
@@ -143,7 +143,9 @@ normative:
143143
name: Annabelle Backman
144144
- ins: M. Scurtescu
145145
name: Marius Scurtescu
146-
date: May 2021
146+
- ins: P. Jain
147+
name: Prachi Jain
148+
date: June 2023
147149
target: https://datatracker.ietf.org/doc/html/draft-ietf-secevent-subject-identifiers
148150
title: Subject Identifiers for Security Event Tokens
149151
CAEP:
@@ -2159,7 +2161,7 @@ SSF events MUST use explicit typing as defined in Section 2.3 of {{RFC8417}}.
21592161
{: title="Explicitly Typed JOSE Header" #explicit-type-header}
21602162

21612163
The purpose is defense against confusion with other JWTs, as described in
2162-
Sections 4.5, 4.6 and 4.7 of {{RFC8417}}. While current Id Token {{IDTOKEN}}
2164+
Sections 4.5, 4.6 and 4.7 of {{RFC8417}}. While current Id Token {{OpenID.Core}}
21632165
validators may not be using the "typ" header parameter, by requiring it for SSF
21642166
SETs a distinct value is guaranteed for future validators.
21652167

@@ -2272,9 +2274,50 @@ specification.
22722274

22732275
# Notices
22742276

2275-
Copyright (c) 2021 The OpenID Foundation.
2277+
Copyright (c) 2023 The OpenID Foundation.
22762278

22772279
The OpenID Foundation (OIDF) grants to any Contributor, developer, implementer, or other interested party a non-exclusive, royalty free, worldwide copyright license to reproduce, prepare derivative works from, distribute, perform and display, this Implementers Draft or Final Specification solely for the purposes of (i) developing specifications, and (ii) implementing Implementers Drafts and Final Specifications based on such documents, provided that attribution be made to the OIDF as the source of the material, but that such attribution does not indicate an endorsement by the OIDF.
22782280

22792281
The technology described in this specification was made available from contributions from various sources, including members of the OpenID Foundation and others. Although the OpenID Foundation has taken steps to help ensure that the technology is available for distribution, it takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this specification or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any independent effort to identify any such rights. The OpenID Foundation and the contributors to this specification make no (and hereby expressly disclaim any) warranties (express, implied, or otherwise), including implied warranties of merchantability, non-infringement, fitness for a particular purpose, or title, related to this specification, and the entire risk as to implementing this specification is assumed by the implementer. The OpenID Intellectual Property Rights policy requires contributors to offer a patent promise not to assert certain patent claims against other contributors and against implementers. The OpenID Foundation invites any interested party to bring to its attention any copyrights, patents, patent applications, or other proprietary rights that may cover technology that may be required to practice this specification.
22802282

2283+
2284+
# Document History
2285+
2286+
[[ To be removed from the final specification ]]
2287+
2288+
-02
2289+
2290+
* added spec version to metadata
2291+
* Added description as receiver supplied
2292+
* added language to make verification and updated events independent of events_supported
2293+
* added top-level sub_id claim. Modified existing language to reflect the use of the sub_id claim
2294+
* updated text to reflect sub_id as a top-level field in verification and stream updated events
2295+
* #46 add stream exists behavior
2296+
* update stream exists to 409
2297+
* Add 'format' to normative examples in CAEP
2298+
* Remove 'format' from stream config
2299+
* Remove subject from stream status (#88)
2300+
* Add reason to GET /status response
2301+
* Make reason look like an enum in the example to indicate how we expect it to be used
2302+
* Fixes #60 - are subjects required
2303+
* Added format field to complex subjects and updated examples (#71)
2304+
* Switch stray '204 OK' to read '204 No Content' (#73)
2305+
* Change 'jwt-id' to 'jwt_id' to match style of other subject formats (#63)
2306+
* resolving issue #45 added explanatory text to Stream Configuration (#68)
2307+
* #28 update delivery method references to URNs (#49)
2308+
* Changed jwks_uri from REQUIRED to OPTIONAL (#47)
2309+
* Sse to ssf (#43)
2310+
* updated SSE to Shared Signals in all files
2311+
* changed source format to md
2312+
* renamed files to be called sharedsignals instead of SSE. No change to the content (#41)
2313+
* Add stream_id to SSE Framework spec as per Issue 4: https://github.com/openid/sse/issues/4
2314+
* Update README with development instructions and fix error in Makefile
2315+
* Added note to PUSH/POLL section about uniqueness requirements for the URLs
2316+
* Add explanation about what an Event Stream is
2317+
* Change terms to Transmitter-Supplied and Receiver-Supplied
2318+
* Pragma is an obsolete HTTP header
2319+
* It's unnecessary to specify the character as UTF-8 in all examples (#10)
2320+
* Fix issue #18 by converting saml-assertion-id to saml_assertion_id to maintain consistent formatting with other subject identifiers (#1)
2321+
* updated backward compatibility language
2322+
* added section for Transmitter Configuration Metadata RISC compatibility
2323+

0 commit comments

Comments
 (0)