GUT-profile-WG / GUT-profile

Repository for the G(rand) U(nified) T(oken) profile
4 stars 1 forks source link

Review mixing capability-based and group-based AuthZ in a single token #4

Open msalle opened 8 months ago

msalle commented 8 months ago

Relevant for WLCG and AARC, but I think we should decide not to have capability-based and group-based AuthZ mixed in a single token. When there is a need for both (perhaps don't know what the audience understands) two separate should be sent.

This is not the same as adding a VO to a capability-based token which would be used for e.g. accounting or setting the context (namespace).