[OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Resource Metadata

Michael Jones <michael_b_jones@hotmail.com> Sat, 14 September 2024 23:48 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BECF1C14F689 for <oauth@ietfa.amsl.com>; Sat, 14 Sep 2024 16:48:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.222
X-Spam-Level:
X-Spam-Status: No, score=-1.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oALH96mMQhSk for <oauth@ietfa.amsl.com>; Sat, 14 Sep 2024 16:48:45 -0700 (PDT)
Received: from BL2PR02CU003.outbound.protection.outlook.com (mail-eastusazolkn19010011.outbound.protection.outlook.com [52.103.11.11]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D73AC14F680 for <oauth@ietf.org>; Sat, 14 Sep 2024 16:48:45 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=gURbvddVEH+IN93Zc0QGYiWPHbb09lpYKOqpgRuyAqOhxfGJa40E5GUC7VqtQOyQmN3Vo942LPJwqImCpi7cjsuySlFk27LY1tdlwYdDxMwVxe0bT0wDEX0Gxf2zf5g40baSdlBHUbyJvN57kX0kYNv+8+4401blsz1NqBKBm5XiiW2SpIB2QBuPHkc/zgpB4fY5IdmT9UdZmbpnGFe54Gn0sx2bflymveSScQewHOwOjPqlAE0jVdTf8jtZtW/GvbnKf6RfqT2kfoYMfrjEbKLzlvOa4ghPDSv/5RU7pyKHSFcE88bwMm5Uf622/2X4aDhvtVnjFqZgJXmFjYtiuA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=go5t5WUzHVzjQTMdc839WnVYs6Pw/5de879soJt8ynM=; b=G3atA6QZ5S0B7XSbxQ5iZeThw6gmHx16vKA+RJNeZUglloyCZRImgEkWhgT4PvZ67dA08yhuHKy7Hxrne9z4tyTwETUpYTXIyw12qpKcvc0jzwLelC2365ON0zKyaORsVge99FK3PDlm+RTd3k2mUROnR0HedmWMus5KJn/n1m1HjvUnuAt9QXM7FTZ9iKwUgQ9B2cQbX1FHDY0shP/ioD1lfHeXWsRBpVqS7UBUrZvWH1Pxd/PnABaFH1RHAcED8on9iC/4QQU0AEl2u41TJzMvwgfR+4XqVRthdHlADXRTVu28Cjd8ouzqWkr7Xut6p77vV0bDzPOiFaFblmv85A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=go5t5WUzHVzjQTMdc839WnVYs6Pw/5de879soJt8ynM=; b=DTlHotkqJ+mRIW2iUqlPjwCHBnXs1yOz1TZXC9LrQ3zFAPbSgw8T6xezLYq/VcxeQ3epLQDYG0JUpQbYCmTN5XO8JF9Z325mTuBQh7zGe9TczJFLSOcmcTZS2YF4oKvw3WolXPKtJ3v4GVSi+En+0arGcMymeis9qWHQvvawIsGUsn3OpekEaDDqfXIJJ2qzrk/K38CJlntJnSm1uLiSGrAJj4j0S+SEJqRQ3x2213OfLSTo7xh57u/rynCAWCzP2gBIfl969Ebt1cYs3PNjOGEg9UypwC86JM9EzuTvlW7tHaYtsv8jUYauBtxXpS++YHrDef4++mOPMTq/wGmd0A==
Received: from PH0PR02MB7430.namprd02.prod.outlook.com (2603:10b6:510:b::9) by CY8PR02MB9565.namprd02.prod.outlook.com (2603:10b6:930:71::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7962.22; Sat, 14 Sep 2024 23:48:43 +0000
Received: from PH0PR02MB7430.namprd02.prod.outlook.com ([fe80::67ac:16c1:95b5:fcdc]) by PH0PR02MB7430.namprd02.prod.outlook.com ([fe80::67ac:16c1:95b5:fcdc%5]) with mapi id 15.20.7962.022; Sat, 14 Sep 2024 23:48:43 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Ralph Bragg <ralph.bragg@raidiam.com>, "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: Feedback on OAuth 2.0 Protected Resource Metadata
Thread-Index: AQHbBlXFqjFEHD4njUKx9v8y7cJU0LJX8+dw
Date: Sat, 14 Sep 2024 23:48:42 +0000
Message-ID: <PH0PR02MB74303B66735DF5D8E6F10E26B7662@PH0PR02MB7430.namprd02.prod.outlook.com>
References: <LNXP265MB0620203F4D97C1AA81D49239F6662@LNXP265MB0620.GBRP265.PROD.OUTLOOK.COM>
In-Reply-To: <LNXP265MB0620203F4D97C1AA81D49239F6662@LNXP265MB0620.GBRP265.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_Enabled=True;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_SiteId=ecb51cf4-27f1-440b-bed5-50fc2ffbea8d;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_SetDate=2024-09-14T03:25:38.9888332Z;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_ContentBits=0;MSIP_Label_e89daa53-33ce-4898-b4b5-ead099c5b005_Method=Standard
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR02MB7430:EE_|CY8PR02MB9565:EE_
x-ms-office365-filtering-correlation-id: 356917c6-8748-4267-8fe0-08dcd517c3e8
x-microsoft-antispam: BCL:0;ARA:14566002|15080799006|461199028|12050799009|8060799006|19110799003|1680799051|9000799047|7092599003|9400799024|4302099013|3412199025|440099028|102099032|1602099012;
x-microsoft-antispam-message-info: VlOIQ6pbolZVNNi7qC8sz00eD5MEX+gaaZnpLqP+mM8gBEIeJGaq611vE7SL4MDSLJVi8UYTIGSIJlLjLZ06QGCAcbDgLce4l5QxyUzMMXnNJ5Ltx/ww7Mn5NQAONJTxdBqo3ZZkK7frR6Bvkjm2qHJwgNutwHjJBhoILEuB0kr352z5hh8nwWtMXnPnqYXcF3NPQVKGdyxTQusQi2lO2M0VzQjtR2pOChIixFeRuDmKwzAyzkD91D86PNGt++BJiAN7tdzKx55rH2pC0SKsLFjo1CZJWzgPOoWwgbIbSp4Q+nKxhy1se3Rq3j/zhVuiRB6JW9PFy7Pz9Y44nbay+6kdCkqP9H6vSKqFTNmmaCroo3h8oZxJd/41mkJaAoiGZKFCDoLhYENijAw0Sga21C+n2AF2vg6kzd+gz7NigtpAkd88OCUlquH7zYbZAZvzscT2w7sA4ZuQVTGI2Pitr5SsiQP7RFckirBAgLYCJk1/wBkTei3uMw9/GC3tLKaX7NNWbgZH6qeG66Aierbw7YkJ3Wjxdct3ASEWk3/NKOCLrXcMCjipsL0gX5okpTVui7LoLBljf/GO/hJehk4OeRHVKnhEuz31SysfHd8mYpgQsslEvjbupg18QU9Z+AqNnQZJ+FOxa1yVGjOjjd1jEevRZVwt1bHIer9V/VUSH7VTe5faUXGF9MMpGG7GKJU/eDYo7u2x6ur578p7oo+Whk7fWeFt65pyv82kBzUyVcACOt49Ng11xjWAYjs9Vz6YRtZaZmTEGLHNfveicTM10VUcCtsHvHU1sTK9GTYF+0WAJKjgmqW4le6nVPNZ/MUwLNdy38TAkjQF033NejSmE8lsVUr+AHfTn2x+OXGol2WoiUcWdUC6FljRV7An2xkRdzDx8keIGVfpWhImvSFoXK7y9AgrVGQC6EGER101j97m0eWrYPCikOBHFlFV49bP
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: yWRtSIP0+TwpHqzuoQUU2CIlwMc6br559FbT+Y8gUn+C+TxTEVSKvfJ5B0RRG/YwOVJncu73ROSoOzCZX86eNlUwMShMnn8+zXDM0DrQ0UO3ojjZ5rGdL85udcmLSKSo4pXglInm9CTaOugzi5i0uNqDQXM3X/ayQduOYpl1tUwYWXxwbE2f1Rjh0by7xzbCdsjMgjv//zQ34xAZIyu5oz7zattsZtlPcr1my/or1+I62OK7m0/8d8KCi3VkpJoR9LDcukbr4sEaRcxgm1DJB1mghHCNo9rXK993MEdXpQ7HFMqx3ueT5++oNdw/1fjjm5znupnbEflXZwyNW9sZriU8fanwm/WrTiEySrfDPW7ih+RJFMdUePhp2yiZR+Qf35UcOAzDj9xZLtYChPjCvHsxLmAexSGddx55HE/Fud2YrwBk5tCdREmxUhsW1ZK63nOTa2Aj+jY6WsL1nLq7peHEBX0q8utiC/Wc60ZCuZaAolNxuyK1bApFP7aIboIhEupIF6P0WOor+75tyLXQsdG5OJOVodQXT4umZeLLYAMUGipf1zxwX/ueMhi8T8RMbsbXys9ZBYzt1P1jZefUAAnLiBqK8gQYgkHXyCBTGYiYgAnQf9EVCoZQrTY57SrEWOAYYSJjynL14XYKQoFOUuTCWj6tyeo/mm/+hevLJGKHwJ3KQfpN7QIjF3unovsHccmrFV9UDCzem7OVErBCylzYndhRkk+oAQWE5jWSO59AH8A3wUUm8WYtsz2zQj1o4c+vrovprH5JtOp+vhtqYr4B9gmzoN18NnV7ZY/fdIMzk42E87cR+25K4zJEhiKKcnMJmpfolA+XQMK5Adyr1aW76DPGb2+hQB4gvNnyATlpsqXPfEpAGMEnsb1c8eB0b3INfc/m0WfdE1DA7EPNNIJT1FvLPvcFLwj59KOQc+jRsbXCy48gyR47RmFN8IAc/hjFTDHu8igddQR/DJ4dymmHCg+jkmAIveBmQOT8RVIoItUXgkTn5HZeOdjXx6cUjMr4vwiAmJBsWEwttmpE3LBxcouhKQM591xtplp5TsVzjRNmGJTwiJpM2hzhM82idARjsF26/5cidRWdOZUCB1BhssGftKurQ+QM+AL9ybHIVV1Mv84onfMIIdrNtEN/CyKhgpgzGqQGK6KPEFtFZ9eBtR/ReXENVWdWVgChykXcpxkNzSy3oOOlVIXuRtmM1RFinUx/I7gJA4CW1UOWulLTahS4AGKoApR93FtgKAw=
Content-Type: multipart/alternative; boundary="_000_PH0PR02MB74303B66735DF5D8E6F10E26B7662PH0PR02MB7430namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-7719-20-msonline-outlook-0f88b.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR02MB7430.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 356917c6-8748-4267-8fe0-08dcd517c3e8
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Sep 2024 23:48:42.7503 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY8PR02MB9565
Message-ID-Hash: QIGM6ZUJ6QW7PCLDTMUDH7AJV44NHLEJ
X-Message-ID-Hash: QIGM6ZUJ6QW7PCLDTMUDH7AJV44NHLEJ
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [OAUTH-WG] Re: Feedback on OAuth 2.0 Protected Resource Metadata
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Bklh7Gp0wa-hbYaEQQb5W44hlMs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata/pull/54 addresses this request.  It reuses the metadata parameter name authorization_details_types_supported from https://www.rfc-editor.org/rfc/rfc9396.html.

                                                                -- Mike

From: Ralph Bragg <ralph.bragg@raidiam.com>
Sent: Friday, September 13, 2024 8:34 PM
To: Michael Jones <mike@self-issued.consulting>; michael_b_jones@hotmail.com; oauth@ietf.org
Subject: Feedback on OAuth 2.0 Protected Resource Metadata

Hi,

Can I please request that additional metadata types for describing resource access requirements be included from the RAR specification (https://datatracker.ietf.org/doc/html/rfc9396#name-relationship-to-the-scope-p) in the

https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-09.html specification.



RAR is an alternative to scopes and the use of only one way to convey authorization to access the resource is recommended in the RAR spec.

Combined use of authorization_details and scope is supported by this specification in part to allow existing OAuth-based applications to incrementally migrate towards using authorization_detailsexclusively. It is RECOMMENDED that a given API use only one form of requirement specification.".



Oauth resource servers that have moved to supporting rar should be able to advertise using the oauth resource metadata specification the rar types that are required to access the resource in a similar way to scopes.



Thank you for your consideration for this change as I understand this draft is in last call.



Kind Regards,

Ralph




Ralph Bragg

Chief Technology Officer

M.



+447890130559

T.



0203 148 6609

ralph.bragg@raidiam.com<mailto:ralph.bragg@raidiam.com>

[https://storage.letsignit.com/icons/designer/socials/Linkedin--circle--black.png]<https://cloud.letsignit.com/collect/bc/652d0421e161c54081b81962?p=TMTQYP7uhVuEibYQ91RsC3IoNUOt5RBT8PxKu46ijB200WFOdFgfuybDSNA7VsIsDfVuTvGEfkoMzngn2LEx6sZgJoSeY6SRq4DADGvENbcrCp3R8bPY3ukqcgnAE1QBOE1aeRl-_3D7UXCGJdZ1M7e1qUDa1Q4HzoARy0RaSJE=>

[https://storage.letsignit.com/5fd527570105a500075428f0/generated/effects_08e3e03b4f71b6a89cf4bd9f429daac0a7f6dd1ccb38a410fc760991.png]

The content of this email is confidential and intended for the recipient specified in message only. It is strictly forbidden to share any part of this message with any third party, without a written consent of the sender. If you received this message by mistake, please reply to this message and follow with its deletion, so that we can ensure such a mistake does not occur in the future.