Re: [OAUTH-WG] WGLC for Cross-Device Flows BCP

2024-04-22 Thread Saxe, Dean
Rifaat, I have a few minor nits in the doc, nothing of significant concern for WGLC. 1. When describing the visuals documenting the flows, there is a step that includes “The user authenticates to the authorization server”. In each case this should include verbiage to indicate that this is

[OAUTH-WG] Cross-Device Flows: Security Best Current Practice Review

2024-04-22 Thread Roy Williams (E+P)
I had promised at the 119 meeting that I would review this document and give feedback. I have completed that document and other than two potential clarification points, I found it to be helpful. The following two areas could be slightly improved: 1. At the end of section (5) there is a

Re: [OAUTH-WG] [External Sender] Re: Transaction Tokens issuance in the absence of incoming token

2024-04-22 Thread George Fletcher
Kai, How would the TTS trust the incoming "subject" value if not signed? Do you have something in mind? Thanks, George On Tue, Apr 16, 2024 at 3:46 AM Kai Lehmann wrote: > Hi, > > > > Sorry for replying to this so late to this thread. Although self-signed > JWTs may help to fill the

Re: [OAUTH-WG] WGLC for Cross-Device Flows BCP

2024-04-22 Thread Rifaat Shekh-Yusef
We have not received any feedback on this document so far. This is a reminder to review and provide feedback on this document. If you reviewed the document, and you do not have any comments or concerns, it would be great if you can send an email to the list indicating that. Regards, Rifaat

Re: [OAUTH-WG] WGLC for OAuth 2.0 Protected Resource Metadata

2024-04-22 Thread Rifaat Shekh-Yusef
All, Hannes and I discussed the status of this document. We believe that this document received significant feedback and a new updated document is needed. Because of that, after a new version is issued, we will start a *second WGCL* on this document. Regards, Rifaat On Fri, Apr 5, 2024 at