ConsumerDataStandardsAustralia / standards-maintenance

This repository houses the interactions, consultations and work management to support the maintenance of baselined components of the Consumer Data Right API Standards and Information Security profile.
41 stars 9 forks source link

CDR Register OpenID Configuration does not specify token signing algorithm support #440

Closed CDR-API-Stream closed 2 years ago

CDR-API-Stream commented 3 years ago

Description

This issue has been raised to track CDR Register issue 169 through the standards maintenance process.

Please refer to CDR Register issue 169 for details

perlboy commented 2 years ago

The Standards do not specify that a Holder is required to use the Register discovery document in the first place, in fact if memory serves the documentation of its existence is a (relatively) recent addition.

Perhaps it should because then it would be possible to avoid needlessly redefining upstream specifications under the auspices of "Client Authentication".

CDR-API-Stream commented 2 years ago

This change was incorporated into release v1.15.0. Refer to Decision 212 for further details.

CDR-API-Stream commented 2 years ago

@perlboy Thanks for your comments.

Feature negotiation and change management are topics we will focus on early this year. Setting expectations on change management with the CDR Register discovery endpoint would be a relevant topic to include in this discussion.

I will provide a link once this decision proposal is created.

CDR-API-Stream commented 2 years ago

Closing as complete