oauth-wg / oauth-transaction-tokens

MIT License
7 stars 10 forks source link

Clarification on additional signatures #91

Closed dteleguin closed 3 weeks ago

dteleguin commented 2 months ago

From 2.4. Benefits of Txn-Tokens:

Through the presence of additional signatures on the Txn-Token, a workload receiving an invocation can also independently verify that specific workloads were within the path of the call before it was invoked.

It is unclear from the document how exactly the additional signatures could be added to the Txn-Token by the workloads within the call chain. Would be nice to provide some details here, or to state that this is out of the scope of the current document.

tulshi commented 3 weeks ago

this issue is outdated. It seems to have been addressed in the new draft.