oidc-sweden / specifications

Specifications for the Swedish OpenID Connect profile
12 stars 0 forks source link

Consider using claims defined in "OpenID Connect for Identity Assurance 1.0" #63

Closed martin-lindstrom closed 7 months ago

martin-lindstrom commented 1 year ago

OpenID Connect for Identity Assurance 1.0 defines some claims that we also are defining in our "Attribute Specification". These are:

OpenID Connect for Identity Assurance 1.0 also defines the nationalities claim that is a string array representing the End-User's nationalities. We define a more generic country-claim, and we may want to remove that definition as well. However, there are more circumstances where we may want to represent a country other than to represent a nationality (in eIDAS for example).

I suggest that we remove our definitions (while still in draft mode).

leifj commented 1 year ago

Does it even make sense to focus our efforts on complex attributes that will be part of the wallet anyway?

martin-lindstrom commented 1 year ago

No, it doesn't. I was just given access to the PID Rule Book for the EUDI Wallet ecosystem, and when browsing it I see that we could get rid of some of our other "private" claims as well.

martin-lindstrom commented 7 months ago

We should not define any of the "general purpose claims". They just don't belong to our spec.