You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: Subject Identifiers for Security Event Tokens
149
151
CAEP:
@@ -2159,7 +2161,7 @@ SSF events MUST use explicit typing as defined in Section 2.3 of {{RFC8417}}.
2159
2161
{: title="Explicitly Typed JOSE Header" #explicit-type-header}
2160
2162
2161
2163
The purpose is defense against confusion with other JWTs, as described in
2162
-
Sections 4.5, 4.6 and 4.7 of {{RFC8417}}. While current Id Token {{IDTOKEN}}
2164
+
Sections 4.5, 4.6 and 4.7 of {{RFC8417}}. While current Id Token {{OpenID.Core}}
2163
2165
validators may not be using the "typ" header parameter, by requiring it for SSF
2164
2166
SETs a distinct value is guaranteed for future validators.
2165
2167
@@ -2272,9 +2274,50 @@ specification.
2272
2274
2273
2275
# Notices
2274
2276
2275
-
Copyright (c) 2021 The OpenID Foundation.
2277
+
Copyright (c) 2023 The OpenID Foundation.
2276
2278
2277
2279
The OpenID Foundation (OIDF) grants to any Contributor, developer, implementer, or other interested party a non-exclusive, royalty free, worldwide copyright license to reproduce, prepare derivative works from, distribute, perform and display, this Implementers Draft or Final Specification solely for the purposes of (i) developing specifications, and (ii) implementing Implementers Drafts and Final Specifications based on such documents, provided that attribution be made to the OIDF as the source of the material, but that such attribution does not indicate an endorsement by the OIDF.
2278
2280
2279
2281
The technology described in this specification was made available from contributions from various sources, including members of the OpenID Foundation and others. Although the OpenID Foundation has taken steps to help ensure that the technology is available for distribution, it takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this specification or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any independent effort to identify any such rights. The OpenID Foundation and the contributors to this specification make no (and hereby expressly disclaim any) warranties (express, implied, or otherwise), including implied warranties of merchantability, non-infringement, fitness for a particular purpose, or title, related to this specification, and the entire risk as to implementing this specification is assumed by the implementer. The OpenID Intellectual Property Rights policy requires contributors to offer a patent promise not to assert certain patent claims against other contributors and against implementers. The OpenID Foundation invites any interested party to bring to its attention any copyrights, patents, patent applications, or other proprietary rights that may cover technology that may be required to practice this specification.
2280
2282
2283
+
2284
+
# Document History
2285
+
2286
+
[[ To be removed from the final specification ]]
2287
+
2288
+
-02
2289
+
2290
+
* added spec version to metadata
2291
+
* Added description as receiver supplied
2292
+
* added language to make verification and updated events independent of events_supported
2293
+
* added top-level sub_id claim. Modified existing language to reflect the use of the sub_id claim
2294
+
* updated text to reflect sub_id as a top-level field in verification and stream updated events
2295
+
* #46 add stream exists behavior
2296
+
* update stream exists to 409
2297
+
* Add 'format' to normative examples in CAEP
2298
+
* Remove 'format' from stream config
2299
+
* Remove subject from stream status (#88)
2300
+
* Add reason to GET /status response
2301
+
* Make reason look like an enum in the example to indicate how we expect it to be used
2302
+
* Fixes #60 - are subjects required
2303
+
* Added format field to complex subjects and updated examples (#71)
2304
+
* Switch stray '204 OK' to read '204 No Content' (#73)
2305
+
* Change 'jwt-id' to 'jwt_id' to match style of other subject formats (#63)
2306
+
* resolving issue #45 added explanatory text to Stream Configuration (#68)
2307
+
* #28 update delivery method references to URNs (#49)
2308
+
* Changed jwks_uri from REQUIRED to OPTIONAL (#47)
2309
+
* Sse to ssf (#43)
2310
+
* updated SSE to Shared Signals in all files
2311
+
* changed source format to md
2312
+
* renamed files to be called sharedsignals instead of SSE. No change to the content (#41)
2313
+
* Add stream_id to SSE Framework spec as per Issue 4: https://github.com/openid/sse/issues/4
2314
+
* Update README with development instructions and fix error in Makefile
2315
+
* Added note to PUSH/POLL section about uniqueness requirements for the URLs
2316
+
* Add explanation about what an Event Stream is
2317
+
* Change terms to Transmitter-Supplied and Receiver-Supplied
2318
+
* Pragma is an obsolete HTTP header
2319
+
* It's unnecessary to specify the character as UTF-8 in all examples (#10)
2320
+
* Fix issue #18 by converting saml-assertion-id to saml_assertion_id to maintain consistent formatting with other subject identifiers (#1)
2321
+
* updated backward compatibility language
2322
+
* added section for Transmitter Configuration Metadata RISC compatibility
0 commit comments