[OAUTH-WG] Weekly github digest (OAuth Activity Summary)

Repository Activity Summary Bot <do_not_reply@mnot.net> Sun, 02 August 2026 09:38 UTC

Return-Path: <do_not_reply@mnot.net>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C13DA12246198 for <oauth@mail2.ietf.org>; Sun, 2 Aug 2026 02:38:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785663486; bh=sZZJlIg1t9Ac22aIo60lVOhb+cKEAz8QH8f73ZhPfMY=; h=From:To:Subject:Date; b=IhrARDgDB/33AEiG5Vi7MOqejK8bRmC1sLe1ga9Ep60pZcDII7mL1y3VLeWnOVzDS 5gMM4JbiCHWfSAoDvBzo+iHQ6VJZUo58nfH28NwRTNtuTZspRvfOuTZNmS7Kjzyx7n r+/TN7KIU6m0IkITKCDicfYFb428R96FtagXljMI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.397
X-Spam-Level:
X-Spam-Status: No, score=-2.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="LJ9QMDNS"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="WAejr//T"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ErlQDR_HfihE for <oauth@mail2.ietf.org>; Sun, 2 Aug 2026 02:38:06 -0700 (PDT)
Received: from fout-a4-smtp.messagingengine.com (fout-a4-smtp.messagingengine.com [103.168.172.147]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5EFAE12245612 for <oauth@ietf.org>; Sun, 2 Aug 2026 02:36:57 -0700 (PDT)
Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.phl.internal (Postfix) with ESMTP id 48B58EC01EF for <oauth@ietf.org>; Sun, 2 Aug 2026 05:36:57 -0400 (EDT)
Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-02.internal (MEProxy); Sun, 02 Aug 2026 05:36:57 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to; s=fm1; t= 1785663417; x=1785749817; bh=2XZM6PhWGBi0HtMcZ2QkPxV09/juM44kb/Y p52x6ucM=; b=LJ9QMDNSYQX5nc58qFcYoQmDIzcFAXo031ljVW07SKwGHUjkdPL gMDj05vySTAzOZ1RBT/SCSZYYVTALJa9e68b/0As8ES5otbo5iNF/0XZ72SqszcR Tp7/lSFRmiLxhpR8KNiqKk9SEdshRbQZm5r1OWFJIfFKQ3ZXZutDR7N+p0IJ1lsj JeTZBMog4zfvbzr57DaCYcIC4WAt3Z1Fc6enZp/G4WhaH8o8A9HQ+m0kCXcH8mQn NgF33PDo/bSu4Ra8bMvpt87v+CxJD6lcN6XlwWBJQVDPW3VQv6LPX3+PM69RKU3S 9CI7PiBLzdANES2VuZWqqxPuR3RvlUfspyA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1785663417; x= 1785749817; bh=2XZM6PhWGBi0HtMcZ2QkPxV09/juM44kb/Yp52x6ucM=; b=W Aejr//TxQjSS7xuF311U6RWJsZYqmG92uSFPhT7HSfM7haYbNvyoxznCWmgKOiFk KH/E5ZgLDmjxiP5q/fe3qHri1xCXiVWOvm+GlmAb0we0+yAKPDcMhoYMl5k1tb0f uJ/T0BLnEim8YLklTdJmYBMuJbM1fSaWqOp2poplf5RkIUQ1u3SI2I0ADZDBhsjk LFjhgOqdOzmlhiNsd+iyBVWQ8PIx+k+QR2NfXweHk4HNVAtPxD2NFYYfx8kuFMK7 6vav2fPP1Rb10tEyfoIAh4gdKl1kHX1/AHG0n0XmryPDT3b5NHNRW82cHIMg594A IBFsafpjAuH0yanzHwbQQ==
X-ME-Sender: <xms:uQ9vajJD8JqTIgaQwwlMxYN8NVhwcUKZMQs0zCCsNCiIKJzWXl6KZQ> <xme:uQ9vatAZYZWUwX1ugh0bDZskMlfHOopGBlARfJnwpnfK9ZaMJD7oGaRNIsjltLHjA CQTZI3NElxqsa_N9fOPhYh2tnlfLwDkj9jH0SssVJnWjgUFqAeQl9o>
X-ME-Received: <xmr:uQ9vamyq-QtoJI0SdFSMEPRmKMW31IdLCn8GJlnMEiwXizxf74RNRCRKgAY2SrlGt_A1Eu5er7eHHvbkJjMpCsLjWSBaKkCK9GMd0ww1qaztcvKiK-DjoFEaelv60zqaZtFL0mA>
X-ME-Proxy-Cause: dmFkZTEvKdpeOECHG4eR18t/tSiJ/HwMk6vz4L9EmJvjCDzW4Y/rMAAum1POQH0WjYWp0B Rzc7rcJfkk8+5BKf7Fjesc7z/tI4ew8pqUn2mWyeEqjxbFwKCsF3nTQaqJccsi2/ykATlP b5eyxkrdUIgUfQHAMfZJQwEdN2d/WLTrC5wXdbbyNg9eoqJpuznbiLLpxoWwr6Lp0W0Pea vaPUaWxAClkhWcXiigm9Gj7EdpFoHz3iB+rlFay88fUrKnkzAJBx4soByxm/wS76E58blt 7C/e0G3QeVY4yVeQuuMFF1h8ZpHTX5qJbKvAINKjaZjLcfCx9suRJyA8DgSeuat7mk3TL/ A14cwdo20tjfH9xQuoDNOIuQUeDtZzFBABOkhdtRJwLbiQqqUNSdV5IPqyCtIVcloWTnMB zdmEnW3v9qL8o1Ur7k3ErSQO0gS7vFe2+t21DEeWwF2G0/Y+8+WCiYQvwnruNj7PUdbzgg 6K0Iu51fbz32kQCaryJi5NT9LYXyJFgY2MGY6Lf+e4CDH5Ca4tCLj0/q3z16/zQYOB44gW RdGMS7M1o843OSt6kjdF8OJPfOxu+cRGjXUsggC+t+Lcs0Sha9aucEzMNzoUZ7kG5waR2Q yVU7ixtL9P28aH3QX4pQZj3UK0TjvudITZxyQSiw7JD6MQTZ8Vk328RwsF4Q
X-ME-Proxy: <xmx:uQ9vapOsmtI5rAUrBCbHR5dMD2qaaxcKxbrAscIlE2cNFZ5YUmNzmQ> <xmx:uQ9vat_3jbBkJr5kCKTX-xjtXxELMBQjQR9V_IjpPC6mNawrUGBsjg> <xmx:uQ9vahplLgXACInOreluFpWi0iFSfyf059oufPEg6__lwO8YetxLaw> <xmx:uQ9van5ds0T6Ycr9t8ey18PWOuGLyTzqYW_PE93L03_9srDbzJlXFQ> <xmx:uQ9vaix5FZGySy7WV74_qCs2W8e3eM9GHO0aiLvEbzt0hp8zi_UoJ1S_>
Feedback-ID: i1c3946f2:Fastmail
Message-Id: <1785663417.3047298.7C11D073@outbound.messagingengine.com>
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <oauth@ietf.org>; Sun, 2 Aug 2026 05:36:56 -0400 (EDT)
Content-Type: multipart/alternative; boundary="===============2884804312388873386=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: oauth@ietf.org
Date: Sun, 02 Aug 2026 02:36:57 -0700
Message-ID-Hash: SWOMFM2KV7DC5V7AUPWJOMXUM4EAFUKE
X-Message-ID-Hash: SWOMFM2KV7DC5V7AUPWJOMXUM4EAFUKE
X-MailFrom: do_not_reply@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Weekly github digest (OAuth Activity Summary)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/qrM5kDuMakE1wulcMMcp7pVFfSQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>



Events without label "editorial"

Issues
------
* oauth-wg/oauth-transaction-tokens (+0/-1/๐Ÿ’ฌ1)
  1 issues received 1 new comments:
  - #183 New Token identifier during replacement (1 by PieterKas)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/183 

  1 issues closed:
  - Using RFC 9396's authorization_details as a claim and for request_context https://github.com/oauth-wg/oauth-transaction-tokens/issues/351 

* oauth-wg/oauth-v2-1 (+1/-0/๐Ÿ’ฌ0)
  1 issues created:
  - How should an Authorization properly implement section 4.1.2.1. Error Response Error Messages (by dfcoffin)
    https://github.com/oauth-wg/oauth-v2-1/issues/253 

* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+1/-2/๐Ÿ’ฌ6)
  1 issues created:
  - clarification for challenge usage needed? (by mickrau)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/218 

  6 issues received 6 new comments:
  - #218 clarification for challenge usage needed? (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/218 
  - #213 RS metadata registration is incomplete (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/213 [ready-for-pr] 
  - #212 Allow for alternative key-bound JWT formats (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/212 [ready-for-pr] 
  - #211 Key-bound refresh tokens are limited to the key lifetime (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/211 [ready-for-pr] 
  - #210 Client ID == assertion subject restriction (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/210 [ready-for-pr] 
  - #200 Draft 9 - Relationship with rfc7521 (1 by paulbastian)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/200 [ready-for-pr] 

  2 issues closed:
  - Draft 9 - Relationship with rfc7521 https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/200 [ready-for-pr] 
  - Client metadata ? https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/170 [discuss] [has-pr] 

* oauth-wg/oauth-identity-assertion-authz-grant (+1/-0/๐Ÿ’ฌ18)
  1 issues created:
  - Sender constraining the ID-JAG via mTLS-cert binding (by kenmccracken-google)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/117 

  3 issues received 18 new comments:
  - #117 Sender constraining the ID-JAG via mTLS-cert binding (2 by mcguinness)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/117 
  - #114 Architectural Conflict in Gateway / Proxy Topology with Public Clients (Section 4.3.3 Audience Check) (8 by kierandotai, leleueri, mcguinness, zekth)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/114 
  - #83 Interoperability gap: JIT provisioning and identity claim negotiation (8 by mcguinness, yaron-zehavi)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/83 [ietf-126] 

* oauth-wg/draft-ietf-oauth-rfc8725bis (+2/-3/๐Ÿ’ฌ2)
  2 issues created:
  - IESG ballot COMMENT: Ketan Talaulikar (No Objection) (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/54 
  - SECDIR: Clarify Nested JWT / multi-signature guidance in ยง3.3 (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/52 

  2 issues received 2 new comments:
  - #54 IESG ballot COMMENT: Ketan Talaulikar (No Objection) (1 by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/54 
  - #52 SECDIR: Clarify Nested JWT / multi-signature guidance in ยง3.3 (1 by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/52 

  3 issues closed:
  - IESG ballot COMMENT: Ketan Talaulikar (No Objection) https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/54 
  - Update Appendix A: changes from RFC 8725 https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/50 
  - SECDIR: Clarify Nested JWT / multi-signature guidance in ยง3.3 https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/52 

* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+1/-0/๐Ÿ’ฌ1)
  1 issues created:
  - Provide guidance on omission of `token_endpoint_auth_method` field (by max-stytch)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/92 

  1 issues received 1 new comments:
  - #92 Provide guidance on omission of `token_endpoint_auth_method` field (1 by ThisIsMissEm)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/92 



Pull requests
-------------
* oauth-wg/oauth-transaction-tokens (+3/-0/๐Ÿ’ฌ1)
  3 pull requests submitted:
  -  (by tulshi)
     
  -  (by PieterKas)
     
  -  (by PieterKas)
     

  1 pull requests received 1 new comments:
  - #366 Refine description of Txn-Token JWT body claims (1 by gffletch)
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/366 

* oauth-wg/oauth-sd-jwt-vc (+1/-0/๐Ÿ’ฌ0)
  1 pull requests submitted:
  -  (by bc-pi)
     

* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+3/-0/๐Ÿ’ฌ4)
  3 pull requests submitted:
  -  (by c2bo)
     
  -  (by paulbastian)
     
  -  (by paulbastian)
     

  2 pull requests received 4 new comments:
  - #219 add considerations for profiling this draft (2 by PieterKas, c2bo)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/pull/219 
  - #215 add clarifications for combined mode (2 by c2bo, panva)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/pull/215 

* oauth-wg/oauth-identity-assertion-authz-grant (+2/-0/๐Ÿ’ฌ0)
  2 pull requests submitted:
  -  (by mcguinness)
     
  -  (by mlajkim)
     

* oauth-wg/draft-ietf-oauth-rfc8725bis (+5/-0/๐Ÿ’ฌ2)
  5 pull requests submitted:
  -  (by yaronf)
     
  -  (by yaronf)
     
  -  (by yaronf)
     
  -  (by yaronf)
     
  -  (by bc-pi)
     

  1 pull requests received 2 new comments:
  - #51 SHOULD NOT to MUST NOT on JWT libraries using none without explicit instruction from caller (2 by bc-pi, yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/51 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps
* https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document


-- 
To have a summary like this sent to your list, see: https://github.com/ietf-github-services/activity-summary