Code Monkey home page Code Monkey logo

Comments (3)

b---c avatar b---c commented on September 15, 2024

The (#Confirmation) bit of that source text points to https://www.ietf.org/archive/id/draft-ietf-oauth-dpop-07.html#Confirmation which describes how to represent the binding for JWT access tokens and in token introspection responses. Other methods are possible, which something that comes from the conceptual foundation of OAuth in general. This draft says how to do it when using JWT or introspection but that's as far as it goes. The #Confirmation section(s) are their own sections and too much to be inlined or condensed.

from draft-dpop.

ioggstream avatar ioggstream commented on September 15, 2024

Question 1:
do the methods described in Section 6.1 - JWK confirmation , and in Section 6.2 - token introspection
satisfy the "MUST" requirements expressed in https://www.ietf.org/archive/id/draft-ietf-oauth-dpop-07.html#section-6 ?

Resource servers MUST be able to reliably identify whether an access token is bound using DPoP and ascertain sufficient information about the public key to which the token is bound in order to verify the binding with respect to the presented DPoP proof

Question 2:

Are the confirmation methods above either recommended or mandatory?

from draft-dpop.

b---c avatar b---c commented on September 15, 2024

1: yes
2: recommended

from draft-dpop.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.