[OAUTH-WG] Weekly github digest (OAuth Activity Summary)
Repository Activity Summary Bot <do_not_reply@mnot.net> Tue, 24 December 2024 00:25 UTC
Return-Path: <do_not_reply@mnot.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 048CCC15153F for <oauth@ietfa.amsl.com>; Mon, 23 Dec 2024 16:25:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.404
X-Spam-Level:
X-Spam-Status: No, score=-2.404 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="glLPjL5o"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="lGrQ35XC"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PzGYU5uphogG for <oauth@ietfa.amsl.com>; Mon, 23 Dec 2024 16:25:02 -0800 (PST)
Received: from fhigh-b3-smtp.messagingengine.com (fhigh-b3-smtp.messagingengine.com [202.12.124.154]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 89C3BC19ECB7 for <oauth@ietf.org>; Mon, 23 Dec 2024 16:24:58 -0800 (PST)
Received: from phl-compute-04.internal (phl-compute-04.phl.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id 0730125401D6 for <oauth@ietf.org>; Mon, 23 Dec 2024 19:24:58 -0500 (EST)
Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Mon, 23 Dec 2024 19:24:58 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to :mime-version:reply-to:subject:subject:to:to; s=fm3; t= 1734999897; x=1735086297; bh=aGem5qkQYRlOHis2x+I9aOlXEDOgEzShe8f uSFb3Bt8=; b=glLPjL5o1CmKRtAXlTQDxxmFxIM9mGOq2FC8eEwzJ4WfvorGLn1 GGPexQ+QZt+jkQboUtznm3n2DO+J1Ln50isxrRPt+qCztNu0lAkScQk7ai9bKC9R eaLu/nr5+wFS3RH9JjHyeyYZ/VyqvJOS8+BatUEZHSi8JwFmERcAuL8IqCkN3WdR gy1or0to6+2TL0iCA/xJ29gea1m60YKTtEGFdZi7SfqEwr27bt78I6kq1u6cH4mp /eDiKqbU2uxQTopWtFRjY9RXlS9jdsH/H8CM1j65uR+r64I7HcqbxuweAMU9M8El f+VQvZwNUVq7003kkNEmyFsjHT0k+BhDuEA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:mime-version :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm2; t=1734999897; x=1735086297; bh=a Gem5qkQYRlOHis2x+I9aOlXEDOgEzShe8fuSFb3Bt8=; b=lGrQ35XCQ71n4SCMA DkIDmEWgk9csSZk94k30ZouUoLA7TJYBNGdeXndfd8bD10YSFqyj7uxiSR81JmhG qmBUmf0wSwBZkWUX7IQSG7J51QJSnVD2BcUV4PguHgeRFtYv1OqBZJUVNFAWjvLK zXKiuFxd/5JgoaMRt1d+TRV8VFb5lJoaf+KiZxdCg5UVaCpUw7TUJEHIqowQtRuI GY6pzLUWK1XXiuVGCEA6ynccLV9iDHwuXoYk8WaBaRhTtbcpSCeSKZIjOX37TUw/ sQ0yNwZUaOoQK3z9d0AW0vy44ImiXhircqiJc16fEGptxlpLcAeo2DVmtRMhEtvE NsQzA==
X-ME-Sender: <xms:Wf9pZ3fZ0LpN1ANI4-mofuPdgGJ6yKBZQhP4paW1ZmniqPDU4wfmZA> <xme:Wf9pZ9Od9yEilvCSO6EUsk-ZO-mv6LeoJ-eFVRxgk4ix0tDp5LxyqnTp5ehS---li 58yxb67G7PepdAXUg>
X-ME-Received: <xmr:Wf9pZwgdHl6OJvAYvjzxqr3E2e4AV8y6mXGFQzobWMqCO8d2kufJO9oTy6Whmw8gABSIleWN34_U7Ix8OItSeKdsSraFCB0XigrxoqbEZIxasK6ahi77nfcLHUPS2_zDvtDV>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefuddruddufedgvdduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdggtfgfnhhsuhgsshgtrhhisggvpdfu rfetoffkrfgpnffqhgenuceurghilhhouhhtmecufedttdenucfpohcuuggrthgvuchfih gvlhguucdlgeelmdenucfjughrpegtggfhvffusegrtddtredttdejnecuhfhrohhmpeft vghpohhsihhtohhrhicutegtthhivhhithihucfuuhhmmhgrrhihuceuohhtuceoughopg hnohhtpghrvghplhihsehmnhhothdrnhgvtheqnecuggftrfgrthhtvghrnhepkeefvddu teejvdefkeehieevuefgfefhteetveegffekffefteffvdelheduieetnecuffhomhgrih hnpehgihhthhhusgdrtghomhenucevlhhushhtvghrufhiiigvpedunecurfgrrhgrmhep mhgrihhlfhhrohhmpeguohgpnhhothgprhgvphhlhiesmhhnohhtrdhnvghtpdhnsggprh gtphhtthhopedupdhmohguvgepshhmthhpohhuthdprhgtphhtthhopehorghuthhhsehi vghtfhdrohhrgh
X-ME-Proxy: <xmx:Wf9pZ4_4KhkCKe9NmZtZk4U3DTom0qjYSrDg3iVUbNy8vOflfyie3g> <xmx:Wf9pZzsTtLQjnBPy7L75mCXLqogOfOzg0kZKn8TsV9H8YuCc9_XTxQ> <xmx:Wf9pZ3HOPR8gPatBiVA6NmB_rbrjY2soUgNRJbQkExi0P1gHVtjT3A> <xmx:Wf9pZ6P9k5WxyHETVs7hvsku9uofabsSrnzgmUt4VhG7WLBf0ni2nQ> <xmx:Wf9pZ84sekzr4A3Cq0xaIjuIH5w9YQny0kgNwoQ3rJFlLJ2vdlurV86I>
Feedback-ID: i1c3946f2:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <oauth@ietf.org>; Mon, 23 Dec 2024 19:24:57 -0500 (EST)
Content-Type: multipart/alternative; boundary="===============0590769697172734820=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: oauth@ietf.org
Message-Id: <20241224002458.89C3BC19ECB7@ietfa.amsl.com>
Date: Mon, 23 Dec 2024 16:24:58 -0800
Message-ID-Hash: M467CQ2J53PGAD3VTBRCUEAKKEXGMDAM
X-Message-ID-Hash: M467CQ2J53PGAD3VTBRCUEAKKEXGMDAM
X-MailFrom: do_not_reply@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Weekly github digest (OAuth Activity Summary)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/oJAwRt-7rdVrd8Jl4ci72463rW4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Events without label "editorial"
Issues
------
* oauth-wg/oauth-browser-based-apps (+2/-2/š¬5)
2 issues created:
- Discussing ID tokens in the Implicit flow deprecation section (by philippederyck)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/59
- Remove reference to TMI-BFF draft (by philippederyck)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/58
5 issues received 5 new comments:
- #59 Discussing ID tokens in the Implicit flow deprecation section (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/59
- #58 Remove reference to TMI-BFF draft (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/58
- #54 Proposed flow for using DPoP with token mediating backend (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/54
- #53 Discussing the usage of localStorage/sessionStorage for session management (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/53
- #51 Working Group Last Call (1 by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/issues/51
2 issues closed:
- Clarify why a BFF belongs to a BFF https://github.com/oauth-wg/oauth-browser-based-apps/issues/56
- Working Group Last Call https://github.com/oauth-wg/oauth-browser-based-apps/issues/51
* oauth-wg/oauth-sd-jwt-vc (+0/-1/š¬0)
1 issues closed:
- use SD-JWT+KB in place of SD-JWT with a Key Binding JWT https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/243
* oauth-wg/oauth-selective-disclosure-jwt (+0/-2/š¬4)
3 issues received 4 new comments:
- #532 SD-JWT Parser requires saving the base64 encoded values? (1 by bc-pi)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/532
- #531 Small (and optional) editorial SD-JWT+KB's spec suggestion: remove whitespace from examples of JSON serialization (2 by bc-pi)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/531 [pending-close]
- #529 Update of Issue #514 (new section 9.12) for the support of Post Quantum cryptography (1 by Denisthemalice)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/529 [pending-close]
2 issues closed:
- Small (and optional) editorial SD-JWT+KB's spec suggestion: remove whitespace from examples of JSON serialization https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/531 [pending-close]
- SD-JWT Parser requires saving the base64 encoded values? https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/532
* oauth-wg/oauth-v2-1 (+1/-0/š¬0)
1 issues created:
- Relations with COAP / RFC9200 (by ioggstream)
https://github.com/oauth-wg/oauth-v2-1/issues/201
* oauth-wg/draft-ietf-oauth-status-list (+1/-3/š¬1)
1 issues created:
- Drop "Methods" from registry names (by paulbastian)
https://github.com/oauth-wg/draft-ietf-oauth-status-list/issues/212
1 issues received 1 new comments:
- #209 Revocation and suspension are not that complicated and there are easy tradeoffs (1 by paulbastian)
https://github.com/oauth-wg/draft-ietf-oauth-status-list/issues/209
3 issues closed:
- new Feedback from IANA Operations Manager https://github.com/oauth-wg/draft-ietf-oauth-status-list/issues/208
- Revocation and suspension are not that complicated and there are easy tradeoffs https://github.com/oauth-wg/draft-ietf-oauth-status-list/issues/209
- Proposed rewording of section 12.5. Unlinkability https://github.com/oauth-wg/draft-ietf-oauth-status-list/issues/207
Pull requests
-------------
* oauth-wg/oauth-browser-based-apps (+3/-1/š¬0)
3 pull requests submitted:
- Clarified the security properties of HttpOnly cookies (by philippederyck)
https://github.com/oauth-wg/oauth-browser-based-apps/pull/61
- remove long paragraph about OIDC (by aaronpk)
https://github.com/oauth-wg/oauth-browser-based-apps/pull/60
- Handled review comments (by philippederyck)
https://github.com/oauth-wg/oauth-browser-based-apps/pull/57
1 pull requests merged:
- Handled review comments
https://github.com/oauth-wg/oauth-browser-based-apps/pull/57
* oauth-wg/oauth-transaction-tokens (+1/-0/š¬0)
1 pull requests submitted:
- Rename azd issue #119 (by gffletch)
https://github.com/oauth-wg/oauth-transaction-tokens/pull/150
* oauth-wg/oauth-sd-jwt-vc (+0/-1/š¬0)
1 pull requests merged:
- fix: adjusting terminology to latest SD-JWT spec
https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/292
* oauth-wg/oauth-selective-disclosure-jwt (+1/-0/š¬3)
1 pull requests submitted:
- Changes aimed at AD's review of the formal appeal (by bc-pi)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/pull/533
2 pull requests received 3 new comments:
- #533 Changes aimed at AD's review of the formal appeal (2 by bc-pi, debcooley)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/pull/533
- #475 ISO/IEC 29100 is too private (1 by bc-pi)
https://github.com/oauth-wg/oauth-selective-disclosure-jwt/pull/475
* oauth-wg/oauth-v2-1 (+0/-1/š¬0)
1 pull requests merged:
- Reorganize Security considerations. See #64
https://github.com/oauth-wg/oauth-v2-1/pull/99
* oauth-wg/draft-ietf-oauth-status-list (+0/-2/š¬2)
1 pull requests received 2 new comments:
- #211 differentiate unlinkability between Issuer-RP and RP-RP (2 by c2bo, tplooker)
https://github.com/oauth-wg/draft-ietf-oauth-status-list/pull/211
2 pull requests merged:
- changes as requested by IANA review
https://github.com/oauth-wg/draft-ietf-oauth-status-list/pull/210
- differentiate unlinkability between Issuer-RP and RP-RP
https://github.com/oauth-wg/draft-ietf-oauth-status-list/pull/211
Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
- [OAUTH-WG] Weekly github digest (OAuth Activity S⦠Repository Activity Summary Bot