[OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Resource Metadata
Michael Jones <michael_b_jones@hotmail.com> Mon, 16 September 2024 18:01 UTC
Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6829C18DBB7 for <oauth@ietfa.amsl.com>; Mon, 16 Sep 2024 11:01:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.222
X-Spam-Level:
X-Spam-Status: No, score=-1.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id swRTXK1hFJ7x for <oauth@ietfa.amsl.com>; Mon, 16 Sep 2024 11:01:25 -0700 (PDT)
Received: from BL2PR02CU003.outbound.protection.outlook.com (mail-eastusazolkn19010005.outbound.protection.outlook.com [52.103.11.5]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B7BA3C1519B3 for <oauth@ietf.org>; Mon, 16 Sep 2024 11:01:25 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Mjuduvfh5jRUh8b1QlEJbEcR38h4I1Uc2wX8U5ncol+tcU0HW+m+FswuJcK36FRGsy0fRR/+pLmW6eW6Fxhe++ReEYitCXNtdz3KmWvHmUxAA2g2CPqOPB5MXPJD9zTEynU5TCL3ylBecgLPe3lKaQco2abEs6PI9GBaOvt3Zu92Do7gvDIRk0mkdvqRlXFvBeCO9M3VH65FDdKMATpWoepJk34riSgu52O0SGo0pFDHBmMV7DuAYH/kBd4TqW5dr7KHMMRl54lOSbKFzp0dWOqMYKEtvsWajbCDX9UGIgVIiX/WVJqJF8FbzMhTWR0i+1gEHpa9hm+0cYPoLHXKGw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=XzFORTcsP2i9oMQnL/t4yU6bdst5Jzaq4bbBvwpWsuY=; b=bCO9rFqnkrJW3bNMfnfcTttYvImKfNR66UYtnUIxWDRn4KhdWiv3OUf+2rhJvxwTtudBz87PCg9LxzF5iiSE4CFj4k8+n6wLZfH26sPnSBdM9yC37lkfrNYhXIEZ4ayOhKdntfGs1ynyq2UtZZq2IDmomiCi3ZfH9C6F84/SrjHp8HJbXB5juOK9OW2kQZO6i5iBXcVPAyVude7Adslswksh9qbAINf6XY7DrYe48LbdAORbciXydi2I3SKwYvUCBPO0I0areIyGqnGfTXuYWy7dnz/z0kI0s+wnHPELORRojK26IydsoA0C2iCt2itG9alvaRwcfOhboOvVJkVEEg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XzFORTcsP2i9oMQnL/t4yU6bdst5Jzaq4bbBvwpWsuY=; b=i5lIuEsJeaaTG0hpEDxK9mKz6YDHYl+EMwkv5f2bZ9ZAW4dG0I8LFvTxdMXCVFmdH8DYv8GbQMLFimbXqTUElhYAhs4JrZugivVo4IXzCDAzT4HpRsFPbGbdZNME40dgK1fMS+MY8UcwherS18hS9fOROacawi3Xizz0IN3ktV7S5IsmBXi3G7476P/JFt7GpF+Ccpmbgt0ddNGq4UjTytO19XdXCr2Z1+LG17dsh7YzpV865mZDBVLnIjdKyhKjZ9UWbvvKw0sEroyup1UwGzeIcTiMo7zB6hVoHm7wtGofRGmcIhsKGqdIds/QlyJhmb/DEbVjIjYfL8+jeULDaw==
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com (2603:10b6:a03:295::14) by CY5PR02MB8870.namprd02.prod.outlook.com (2603:10b6:930:42::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7962.24; Mon, 16 Sep 2024 18:01:23 +0000
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::6394:e79c:c32a:4c6a]) by SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::6394:e79c:c32a:4c6a%3]) with mapi id 15.20.7962.022; Mon, 16 Sep 2024 18:01:23 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Ralph Bragg <ralph.bragg@raidiam.com>, "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: Feedback on OAuth 2.0 Protected Resource Metadata
Thread-Index: AQHbBlXFqjFEHD4njUKx9v8y7cJU0LJX8+dwgALD+LA=
Date: Mon, 16 Sep 2024 18:01:22 +0000
Message-ID: <SJ0PR02MB743941532AE011C6D6E01066B7602@SJ0PR02MB7439.namprd02.prod.outlook.com>
References: <LNXP265MB0620203F4D97C1AA81D49239F6662@LNXP265MB0620.GBRP265.PROD.OUTLOOK.COM> <PH0PR02MB74303B66735DF5D8E6F10E26B7662@PH0PR02MB7430.namprd02.prod.outlook.com>
In-Reply-To: <PH0PR02MB74303B66735DF5D8E6F10E26B7662@PH0PR02MB7430.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_Enabled=True;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_SiteId=ecb51cf4-27f1-440b-bed5-50fc2ffbea8d;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_SetDate=2024-09-14T03:25:38.9888332Z;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_ContentBits=0;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_Method=Standard
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB7439:EE_|CY5PR02MB8870:EE_
x-ms-office365-filtering-correlation-id: d69e7541-6551-499e-1ed5-08dcd679931d
x-microsoft-antispam: BCL:0;ARA:14566002|7092599003|9400799024|15080799006|9000799047|19110799003|1680799051|8060799006|461199028|12050799009|102099032|1602099012|440099028|3412199025|4302099013;
x-microsoft-antispam-message-info: I74bl71mH/hKGFiZFdvCVhpnZvDbAfC73+kPbT1RlSkfHzy+3IdMQbHXWsNbis5lV2weIymxs0rHAkcZfnmsdeW76cmGIV8PsNfES3uDmX9T28aFyJCbfxYGvWmuLy5TJpf70X15lAKHnfiDC0BjzaKAotP4waE4ec89ceduiKOeie9bIRhz7RvwSq122i18RzirsBp2jIrDx7YJzNohzFJgoykS70Zu0eMzsa1WU2u27UPj3SgZzeSAE05U8a4wfFF4zEqJmPpufKNptHW3q3spX9YQ9S11i1Mx/QAQ3mVMouCU27nM62HMuaJRpCkKuUAeb2Xhn+r4P1vO1AcdSZTfJzMUJiiPa+9KtWE41lOksQJlqftB0qyhcYGmfRKJulN/zpI8CZOUjNqRlvIrQ6Tv0tYnbvv25TO4mdJZv8/9JuFRUMJRlmknfSK5rs5Gl1Vxkar8baP4c3LWjzo8qY8z2/lLmMwb2ZhsNhnbm2OlFxXI1aoy2c/DTMGeWO0aldetsPO6iVs1AfDbiwVPYpt3HatPHC+xYzL/UPmjMzI9lBTdTaT0CXzfhImkmvGkcD0PAHgYuy+MAzPnKa67vFcBGgg1Wjj6Qacq7mtKAgywdm4iah8oP0/w1Vi/YIm1pAMuhNeKjAdm53azMWIllzqnlum1Ltfdqi9ZPpfy+llLzQSLAev8o4tBoNrJVLbDKFikbjo/mw8MWOuRullGCMsJVj+ELRpE1a1XBEwzITb2nX9U1o+jRGnFIG1dooAg8PsV1sDv/+nziiF5bD9PcNumbALV1BV1a3LRblM2gcm05UnKixJU4GAsrGFk2/gJLT+tLoC0OOQFouBBQ5vU9h+KXtaxmarNqrqeGSRjcIcx5Xk/tLGRySD22ijaohSGA2YhwXBpZbx7qTsR0kt/eNlEr3BondS6JFSLZgEKjxoYHgr/qTxJp5aWpz6EmsWt
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: rA+mK3poSZeDIgzrH/9JD9n3DEzTRekD+cR6fz8bS/zVmqzsO9wpyT06OjJT3nkMvSeVirsJqYSZwnyLOdBrL4bbjCsXrfiYjZj1yAUhFBp6owB2cDoeOBqSwAOJ6rn02IlPYtdTF8oOdVyUvQqxfuhg8VBR4O7ORaZNWloFEiYwyDZ1FDvFQfpEKXmRlrrt1+3C01sC8d24gwc2FT8us8CxcVACnVaNnjPZwUImWc+IIWkhcJybRVfWluNoRQC1asO/u+OFOsbp/UCOW854jMC21Oeo81iQIDbaYFuawkEZnvyqYhhyO4m1aBWJmTi8tqmU2YM5/iVhng50LFGFGXLF2WboUHcM2QawIzEln2cuSiVE2E2WhVgKGwMzl05/a2e33pDZJVc43h3z8I8lqIp4mM8S6ESwWzNurUK//Qcr4flGNlnwDrinRa4qTz09kpp7ki8A0lDc2ws9EF48FAWv0PcctoMhuV/pzVdDhXdXcymPkOpIwk0nuvGHUM0nMcXMPR2a5QYXaAxifV7fg8AVpoknIyAgG3BKWnU2qEearKewlePKALjygoamn1SGBfy/NUDRHZ4lW83aAgin6Dm28LvYIfMAa0UnF1rbH7dFm+SpMJ2nrAHEnkRA7QjjrHlRN1802bM6AcqDShirkHD2ofSlpi3PGEVP/Mt+Fo7qpyee4AHRAsTGCG8BspcGIyUUiJZKJJQzKzy/FhmoA/Z2/WcqYmRXDMCCgKFTX966gP7CfXXX7NA+7AaZwvGN9TyeJO0w83P3gb/G9d1Dqth20C4Db7tG280nk1k/Fx3n63E9vUchL4djjz8XlflOuFzFtoe8cZw5aUiGBj8FgCPTUdVHO05WJOAGp9sn1vBYm9/uavC+J0AERdh014Q4fD32y1YHfdrZJHl+vY2exIce05ilsySvIQj6ERko72XNPTVU3vnpUUW2QFqHBwaI+UX8dhllfFbhwB5BOmjlqsnaOxOwCZwL7DDquwAnPlQbrm5KtRvI0OeUufG3O+ECx6W82m7ovq+fIFaWH6NbkHG9VKFsuHSIillvVRML1LSCc4j5rG8Z42lWR6hFxx3hSNyrgWxhC7bt6VtnXJQhwQoMojbHzRLdM3kxU3P0JEr4T5wVURxBqLazkQOk9x+KItrMhmlXmLEDp9hes1yCFcIG9haM4AunhQllnyd6qhTojlbinXTuoEzfMPIPADDxAYPg2KQLN6FuN940JT4zFr9PY+tIGTn+U96LyoRiMQU=
Content-Type: multipart/alternative; boundary="_000_SJ0PR02MB743941532AE011C6D6E01066B7602SJ0PR02MB7439namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-99c3d.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB7439.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: d69e7541-6551-499e-1ed5-08dcd679931d
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Sep 2024 18:01:22.7151 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY5PR02MB8870
Message-ID-Hash: W4VBKB3WEC424AZE5ZCPSJAXPQKQNYTY
X-Message-ID-Hash: W4VBKB3WEC424AZE5ZCPSJAXPQKQNYTY
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Resource Metadata
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/AUJscdAmWO25-W9BeG495WLkmHg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
This is addressed in https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-10.html. -- Mike From: Michael Jones Sent: Saturday, September 14, 2024 4:49 PM To: Ralph Bragg <ralph.bragg@raidiam.com>; oauth@ietf.org Subject: RE: Feedback on OAuth 2.0 Protected Resource Metadata https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata/pull/54 addresses this request. It reuses the metadata parameter name authorization_details_types_supported from https://www.rfc-editor.org/rfc/rfc9396.html. -- Mike From: Ralph Bragg <ralph.bragg@raidiam.com<mailto:ralph.bragg@raidiam.com>> Sent: Friday, September 13, 2024 8:34 PM To: Michael Jones <mike@self-issued.consulting<mailto:mike@self-issued.consulting>>; michael_b_jones@hotmail.com<mailto:michael_b_jones@hotmail.com>; oauth@ietf.org<mailto:oauth@ietf.org> Subject: Feedback on OAuth 2.0 Protected Resource Metadata Hi, Can I please request that additional metadata types for describing resource access requirements be included from the RAR specification (https://datatracker.ietf.org/doc/html/rfc9396#name-relationship-to-the-scope-p) in the https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-09.html specification. RAR is an alternative to scopes and the use of only one way to convey authorization to access the resource is recommended in the RAR spec. Combined use of authorization_details and scope is supported by this specification in part to allow existing OAuth-based applications to incrementally migrate towards using authorization_detailsexclusively. It is RECOMMENDED that a given API use only one form of requirement specification.". Oauth resource servers that have moved to supporting rar should be able to advertise using the oauth resource metadata specification the rar types that are required to access the resource in a similar way to scopes. Thank you for your consideration for this change as I understand this draft is in last call. Kind Regards, Ralph Ralph Bragg Chief Technology Officer M. +447890130559 T. 0203 148 6609 ralph.bragg@raidiam.com<mailto:ralph.bragg@raidiam.com> [https://storage.letsignit.com/icons/designer/socials/Linkedin--circle--black.png]<https://cloud.letsignit.com/collect/bc/652d0421e161c54081b81962?p=TMTQYP7uhVuEibYQ91RsC3IoNUOt5RBT8PxKu46ijB200WFOdFgfuybDSNA7VsIsDfVuTvGEfkoMzngn2LEx6sZgJoSeY6SRq4DADGvENbcrCp3R8bPY3ukqcgnAE1QBOE1aeRl-_3D7UXCGJdZ1M7e1qUDa1Q4HzoARy0RaSJE=> [https://storage.letsignit.com/5fd527570105a500075428f0/generated/effects_08e3e03b4f71b6a89cf4bd9f429daac0a7f6dd1ccb38a410fc760991.png] The content of this email is confidential and intended for the recipient specified in message only. It is strictly forbidden to share any part of this message with any third party, without a written consent of the sender. If you received this message by mistake, please reply to this message and follow with its deletion, so that we can ensure such a mistake does not occur in the future.
- [OAUTH-WG] Feedback on OAuth 2.0 Protected Resour… Ralph Bragg
- [OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Re… Michael Jones
- [OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Re… Michael Jones