oauth-wg / oauth-selective-disclosure-jwt

https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/
Other
56 stars 30 forks source link

introduction rewrite #467

Open dickhardt opened 2 weeks ago

dickhardt commented 2 weeks ago

provide more context on what the problem is and why this work is happening, with a summary of how it works

deleted spurious language that reads like a patent application

rohanmahy commented 2 weeks ago

I am generally OK with a much more concise introduction (but I don't find the current Introduction offensive either). If we were to use a shorter intro I would want to see the following addressed:

  1. Mention that you can create an SD-JWT for an arbitrary JWS (not just a JWT).
  2. Reintroduce a casual introduction of the terms "Claims" and "Disclosures", as this was very useful
  3. Spell out SD-JWT on first use
  4. s/the verifier would like assurance/the holder can optionally provide assurance/
  5. Add back this sentiment "While JWTs with claims describing natural persons are a common use case, the mechanisms defined in this document are also applicable to other use cases."
bc-pi commented 2 days ago

Thanks @rohanmahy, I generally agree with that.

Note that @danielfett has kindly (foolishly?) said he'd take a pass at reviewing or refining or rewriting or reworking this and/or the current (unoffensive, thanks!) Introduction.