Closed jricher closed 1 year ago
@yaronf we've addressed the checked boxes either in comments on the list or in the linked PR #497. At the moment the editors do not believe any text changes should happen for the remaining unchecked items, but we would like your input into the conversation.
For this:
In general the logic of Sec. 5.3 implies that the AS needs to keep track of all tokens
The new text in that section describes how an AS could keep track of only the latest state of a grant request. We believe this addresses the concern here. In regard to revocation, not all tokens can be actively revoked by the AS in practice. In many systems, the AS relies on expiring tokens with a short lifetime to ensure eventual system consistency.
Master issue to track comments from @yaronf
mode
required field"key
by value, there's a lot of complexity and possible security issues as the Client tries to correlate it to known keys. We should RECOMMEND to use the key reference (Sec. 7.1.1) mechanism instead.error
key as a string"