[OAUTH-WG] Weekly github digest (OAuth Activity Summary)

Repository Activity Summary Bot <do_not_reply@mnot.net> Sun, 05 October 2025 07:41 UTC

Return-Path: <do_not_reply@mnot.net>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5A0466D81F49 for <oauth@mail2.ietf.org>; Sun, 5 Oct 2025 00:41:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.397
X-Spam-Level:
X-Spam-Status: No, score=-2.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="a2VY6wVN"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="UY9tGPh6"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cYzVPtf_Ludz for <oauth@mail2.ietf.org>; Sun, 5 Oct 2025 00:41:33 -0700 (PDT)
Received: from fout-a5-smtp.messagingengine.com (fout-a5-smtp.messagingengine.com [103.168.172.148]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id AB8456D80CD1 for <oauth@ietf.org>; Sun, 5 Oct 2025 00:40:03 -0700 (PDT)
Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.phl.internal (Postfix) with ESMTP id 968E1EC01BF for <oauth@ietf.org>; Sun, 5 Oct 2025 03:40:03 -0400 (EDT)
Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-02.internal (MEProxy); Sun, 05 Oct 2025 03:40:03 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to; s=fm3; t= 1759650003; x=1759736403; bh=kOkVjq3JUPkDYej3etpIp34RzfCZjt0unwZ WfXbCQoU=; b=a2VY6wVNEB7XHkj3izokdFJi2qQZYz/TpYYdddqFfZ77TSCSBuf uxS8kndZx1olMNOclWEInf/6Zjr4RDnUJCHRnLXR5tXivZTCs5HT/ursLnSfpI5L SrVGFJkAHsSin4CMsuQuyYJVbI0tDKNAGgKcr94BoeyV3K6x6Q5zhjS/4Q6fkC7S iHCtuUp27yBkKUQ/5t9bhgVyc2Ru2ZeaYNRpbzCabPBk5W2NJIiyyXjSqtZh3HQa ZYuuWO8gyqDP29GfiH0lSLIAVdpIJNh7ItB3GPpFctWOdsEzpOMI+c0+z29ZUFy1 juaz5hCKoBJNUePOuEDak/SBWx+3hsuxh3w==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1759650003; x= 1759736403; bh=kOkVjq3JUPkDYej3etpIp34RzfCZjt0unwZWfXbCQoU=; b=U Y9tGPh6i4DV0s3+C5GD8wTYA+kWqz7UY4GCHaO4UgkgsFgYlqMv4nzQ05txVyQ9N clOnkVjmyJbBg6bMsjrziOJifdiv2tWIrqQqYtx+hKKpyeYw8N/C8Cu1KCAmjwiq iAHtwqsrO5HTzj6f7triI96G3nnGXdIyDlPS7dxFbf2CBBA8eAwgaHgtQ5gW4Xks NnqrxYRI/LujnhcNfr66bnkksUgdehofib4oT/XBkDmytEUrlQGokWR8KUIKVFUZ d00IH2zJr5a40/SvELF98fJZYAWzTo+xcg9+nhkRG3m7T63kSOXxCyuF2KDnNiUb HNQNpbLTBtJ6OPNSl3gwg==
X-ME-Sender: <xms:0yDiaLN9DV8yDyl2vSR2YrStEBNjIuSaxOiG34MwIB6TJ6c6Dy82Ig> <xme:0yDiaL3oTiXCP4Bv1_JixLGvIA8af576LZI6GDtk_C3rV20Xu61qYY5ceHCk_DNtL RqHWPT8ji8jT8utv6uDC4CtHEqW6eUPb-OpWbPh4GiMaLHpndW5K3c>
X-ME-Received: <xmr:0yDiaFWzn0QJ5jptSKP7FNbgd480iwYBPhMoe3iB_Mu6_YsuPExp4hnjgJbjkjEgxiwd8CyD6zLiObJtxcHLBgsxuOxO9jXEIeafAZhFxpGuO3EsVKy4jZM_Ck6Oj_11otgn>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeeffedrtdeggdelgedtkecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecupfhoucgurghtvgcufhhivghlugculdegledmnecujfgurh eptggghffvufesrgdttdertddtjeenucfhrhhomheptfgvphhoshhithhorhihucettght ihhvihhthicuufhumhhmrghrhicuuehothcuoeguohgpnhhothgprhgvphhlhiesmhhnoh htrdhnvghtqeenucggtffrrghtthgvrhhnpeekfedvudetjedvfeekheeiveeugfefhfet teevgeffkefffeetffdvleehudeiteenucffohhmrghinhepghhithhhuhgsrdgtohhmne cuvehluhhsthgvrhfuihiivgepvdenucfrrghrrghmpehmrghilhhfrhhomhepughopghn ohhtpghrvghplhihsehmnhhothdrnhgvthdpnhgspghrtghpthhtohepuddpmhhouggvpe hsmhhtphhouhhtpdhrtghpthhtohepohgruhhthhesihgvthhfrdhorhhg
X-ME-Proxy: <xmx:0yDiaMjNGWIBIUzmPmCcfpsOUJpmbIMJpD8BHU9wbUV0PXboNR4udg> <xmx:0yDiaHC5YJTgjS78p2wWpMo5KfxHNSQbSGByGkYIbcIaoylxS1PL0w> <xmx:0yDiaNcVf48hMvV1K_osyIKjik1s3pz9zZfkuJwsb8AwKuwOO5KlHA> <xmx:0yDiaPdrFHwQs8h0OJopkxW2hmtzNXiL403mVPPkWTE6GcWe82kRtA> <xmx:0yDiaFWO46iOFbUZY1BMeBFF5grDzF45OXoGj0OY-q0Z0wFW7uGPnPeg>
Feedback-ID: i1c3946f2:Fastmail
Message-Id: <1759650003.2569768.28D8BCAD@outbound.messagingengine.com>
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <oauth@ietf.org>; Sun, 5 Oct 2025 03:40:03 -0400 (EDT)
Content-Type: multipart/alternative; boundary="===============3724594551207395025=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: oauth@ietf.org
Date: Sun, 05 Oct 2025 00:40:03 -0700
Message-ID-Hash: ZENTVZSTXKKGJRFOQEZHSWITUVXVKWCE
X-Message-ID-Hash: ZENTVZSTXKKGJRFOQEZHSWITUVXVKWCE
X-MailFrom: do_not_reply@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Weekly github digest (OAuth Activity Summary)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/cyZwkT3CnJePBHAr8AJvpuShblQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>



Events without label "editorial"

Issues
------
* oauth-wg/oauth-transaction-tokens (+0/-2/šŸ’¬2)
  2 issues received 2 new comments:
  - #206 Relation of purpose to scope validated at API gateway (1 by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/206 
  - #200 Constrain txn-token header field to a single value (1 by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/200 [WGLC Feedback] 

  2 issues closed:
  - Rationale for 'txn' being REQUIRED https://github.com/oauth-wg/oauth-transaction-tokens/issues/193 [WGLC Feedback] 
  - Revise Normative Langugage https://github.com/oauth-wg/oauth-transaction-tokens/issues/210 [WGLC Feedback] 

* oauth-wg/oauth-sd-jwt-vc (+0/-1/šŸ’¬9)
  6 issues received 9 new comments:
  - #355 A new field called "Issuer Authorization URI - "iss_auth"" (1 by cre8)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/355 
  - #346 Support of the default Issuer Signature Mechanism. Required or not? (1 by bc-pi)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/346 [discuss] 
  - #326 No more DIDs in 3.5 of draft 10 (1 by danielfett)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/326 
  - #323 Should `sd` `allowed` be used by issuers? (4 by babisRoutis, bc-pi)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/323 
  - #314 Declaration of arrays to the type metadata. (1 by bc-pi)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/314 [Ready-for-PR] 
  - #223 I18N for Metadata (1 by bc-pi)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/223 [discuss] [Ready-for-PR] [metadata] [PRIO] 

  1 issues closed:
  - No more DIDs in 3.5 of draft 10 https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/326 

* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+1/-0/šŸ’¬2)
  1 issues created:
  - Attestation-based authenticated Client. Public or Confidential? (by babisRoutis)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/152 

  1 issues received 2 new comments:
  - #152 Attestation-based authenticated Client. Public or Confidential? (2 by babisRoutis, jogu)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/152 

* oauth-wg/oauth-identity-assertion-authz-grant (+1/-0/šŸ’¬2)
  1 issues created:
  - Add scope to 6.1 processing rules (by aaronpk)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/49 

  1 issues received 2 new comments:
  - #39 Adopt Tenant Claim from OpenID Enterprise Extensions for ID-JAG (2 by mcguinness, meghnadubey)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/39 

* oauth-wg/draft-ietf-oauth-rfc8725bis (+0/-1/šŸ’¬0)
  1 issues closed:
  - Comments from Dan Moore https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/14 

* oauth-wg/draft-ietf-oauth-rfc7523bis (+0/-1/šŸ’¬2)
  2 issues received 2 new comments:
  - #14 changes after changes from one morning in Bangkok (1 by bc-pi)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/issues/14 
  - #9 Given the suggested changes, how should a client use a SAML assertion as authorization grant? (1 by panva)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/issues/9 

  1 issues closed:
  - Given the suggested changes, how should a client use a SAML assertion as authorization grant? https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/issues/9 



Pull requests
-------------
* oauth-wg/oauth-transaction-tokens (+3/-2/šŸ’¬0)
  3 pull requests submitted:
  - Remove prohibition on returning expires_in and scope (by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/259 
  - `txn` remains unchanged in a replacement transaction token (by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/258 
  - Change to Standards Track from Informational (by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/257 

  2 pull requests merged:
  - `txn` remains unchanged in a replacement transaction token
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/258 
  - MUST instead of MAY on transaction lifetime
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/256 

* oauth-wg/oauth-sd-jwt-vc (+0/-0/šŸ’¬6)
  2 pull requests received 6 new comments:
  - #359 Proposal for recommendation for sd and how extended types use it (1 by bc-pi)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/359 
  - #335 fix: update logo and background structure (5 by bc-pi, cre8)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/335 

* oauth-wg/draft-ietf-oauth-rfc8725bis (+0/-2/šŸ’¬0)
  2 pull requests merged:
  - More substantial edits by Dan Moore
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/25 
  - Dan Moore's comments - the editorial part
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/23 

* oauth-wg/draft-ietf-oauth-rfc7523bis (+2/-0/šŸ’¬2)
  2 pull requests submitted:
  - misc additional changes  (by bc-pi)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/pull/19 
  - client to ensure JAG audience makes sense (by bc-pi)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/pull/18 

  2 pull requests received 2 new comments:
  - #19 misc additional changes  (1 by bc-pi)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/pull/19 
  - #18 client to ensure AAG audience makes sense (1 by bc-pi)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/pull/18 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps


-- 
To have a summary like this sent to your list, see: https://github.com/ietf-github-services/activity-summary