ietf-wg-gnap / gnap-core-protocol

142 stars 26 forks source link

Review comments from Yaron #493

Closed jricher closed 1 year ago

jricher commented 1 year ago

Master issue to track comments from @yaronf

jricher commented 1 year ago

@yaronf we've addressed the checked boxes either in comments on the list or in the linked PR #497. At the moment the editors do not believe any text changes should happen for the remaining unchecked items, but we would like your input into the conversation.

jricher commented 1 year ago

For this:

In general the logic of Sec. 5.3 implies that the AS needs to keep track of all tokens

The new text in that section describes how an AS could keep track of only the latest state of a grant request. We believe this addresses the concern here. In regard to revocation, not all tokens can be actively revoked by the AS in practice. In many systems, the AS relies on expiring tokens with a short lifetime to ensure eventual system consistency.