[art] draft-ietf-oauth-status-list-13 ietf last call Artart review

John Levine via Datatracker <noreply@ietf.org> Mon, 24 November 2025 02:36 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: art@ietf.org
Delivered-To: art@mail2.ietf.org
Received: from [10.244.8.105] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id DEECC8F42A1C; Sun, 23 Nov 2025 18:36:44 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: John Levine via Datatracker <noreply@ietf.org>
To: art@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.54.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <176395180469.2160358.17562138055606795326@dt-datatracker-5bd94c585b-wk4l4>
Date: Sun, 23 Nov 2025 18:36:44 -0800
Message-ID-Hash: U45NPVFODN2ZDIUQOYJRXP2XPLI47N7J
X-Message-ID-Hash: U45NPVFODN2ZDIUQOYJRXP2XPLI47N7J
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-art.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-oauth-status-list.all@ietf.org, last-call@ietf.org, oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: John Levine <johnl@taugh.com>
Subject: [art] draft-ietf-oauth-status-list-13 ietf last call Artart review
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/art/xsiOPSAO1dMnbg2IrgA5xbTiWG4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Owner: <mailto:art-owner@ietf.org>
List-Post: <mailto:art@ietf.org>
List-Subscribe: <mailto:art-join@ietf.org>
List-Unsubscribe: <mailto:art-leave@ietf.org>

Document: draft-ietf-oauth-status-list
Title: Token Status List (TSL)
Reviewer: John Levine
Review result: Ready

While I am familiar with the bits of technology this draft uses, I am not very
familiar with the whole token ecosystem, so this review is somewhat like one
written by a reviewer who arrived during the third act of a five act opera. The
description of the various encodings and embeddings are clear enough, and the
discussions of threats, particularly using huge sets of status items to keep
publishers from knowing which item you're looking for, makes sense.