oauth-wg / oauth-selective-disclosure-jwt

https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/
Other
57 stars 31 forks source link

The format used to carry both the SD-JWT and the Disclosures is unclear #499

Closed Denisthemalice closed 2 weeks ago

Denisthemalice commented 2 weeks ago

The third sentence of the second paragraph in Section 3.1. SD-JWT and Disclosures states:

The Disclosures are sent to the Holder as part of the SD-JWT in the format defined in Section 4.

The first sentence states:

An SD-JWT, at its core, is a digitally signed JSON document containing digests over the selectively disclosable claims with the Disclosures outside the document.

Hence, the Disclosures are NOT included in the Issuer-signed SD-JWT. Change the third sentence of the second paragraph into:

The Disclosures are sent to the Holder in addition to the SD-JWT.