-
Notifications
You must be signed in to change notification settings - Fork 18
Open
Labels
spec:InteropIssues with the interop spec.Issues with the interop spec.
Description
From a recent discussion with @thomasdarimont we had some about the text around https://github.com/openid/sharedsignals/blob/main/openid-caep-interoperability-profile-1_0.md#authorization-server
Questions:
- Does the profile mandate the user of bearer access tokens (I think it can be read that way), or are DPoP or MTLS sender constrained tokens permitted to be used?
- I believe the profile does at least allow the user of bearer access tokens, are we comfortable with that given e.g. https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf is recommending the use of bound tokens?
- Have we actually seen the use of the authorization code flow to obtain an access token for SSF usage? It's not something supported by the conformance tests and as far as I know no one has raised it as an issue so maybe that mode could be removed? If it can't be removed maybe we could at least declare it out of scope for certification for now?
[depending on the answers to these questions I think it would be good to include some clarifications into the spec to make it clearer.]
Metadata
Metadata
Assignees
Labels
spec:InteropIssues with the interop spec.Issues with the interop spec.