Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Extensibility of azd and rctx #80

Open
tulshi opened this issue Mar 26, 2024 · 4 comments
Open

Extensibility of azd and rctx #80

tulshi opened this issue Mar 26, 2024 · 4 comments
Assignees

Comments

@tulshi
Copy link
Collaborator

tulshi commented Mar 26, 2024

From Yaron's feedback email
extensibility: please say explicitly that arbitrary claims may be added to the "azd" (and "rctx"?) objects. There is no IANA registry for either. Note that having 3 predefined attributes complicates the situation a bit - what happens if we want a 4th one? Also mention that any additional attributes are local to the trust domain.

@tulshi
Copy link
Collaborator Author

tulshi commented Jun 14, 2024

TraTs are unique within a trust domain, so do we really need an IANA registry for this? We can add a statement that specifies we can add any sub claims appropriate for the specific trust domain.

@tulshi
Copy link
Collaborator Author

tulshi commented Jun 14, 2024

We need to add the azd, purp, and rctx claims to the JWT claims registry. A question we need to address is how the RAR authorization_details and azd claims differ / coexist. We should do a PR that describes this. We can bring this up as a question in Vancouver.

@yaronf
Copy link

yaronf commented Jun 15, 2024

Even within a trust domain we may want interoperability between multiple vendor solutions. And there will be token translation services that exchange/translate TraTs between trust domains. All of these would benefit from registering claims.

@tulshi
Copy link
Collaborator Author

tulshi commented Jun 21, 2024

I look forward to discussing this in Vancouver

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants