aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
10 stars 8 forks source link

`auth_session` DPoP binding #24

Closed aaronpk closed 10 months ago

aaronpk commented 1 year ago

Do we need to have a DPoP parameter to bind the device session value?

aaronpk commented 1 year ago

Without DPoP binding, device session values should be one-time use.

PieterKas commented 1 year ago

DPoP Section 4.2 defines the extension mechanism.

aaronpk commented 10 months ago

We can define a new parameter ash (auth session hash) to include the hash of the auth_session in the DPoP proof:

https://datatracker.ietf.org/doc/html/rfc9449#name-dpop-proof-jwt-syntax