[OAUTH-WG] Weekly github digest (OAuth Activity Summary)

Repository Activity Summary Bot <do_not_reply@mnot.net> Sun, 16 August 2026 07:56 UTC

Return-Path: <do_not_reply@mnot.net>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 073A812A886F2 for <oauth@mail2.ietf.org>; Sun, 16 Aug 2026 00:56:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786867015; bh=hQ2NFsnuv29JCUz0ZPxmyjNr9a2WLhR4aAoiqdKmXU4=; h=From:To:Subject:Date; b=cc81IXfxIlUvbIzry9UeOod/lZ7IbGuIBkU+SKe1LLcyWXXDeFzzMVgqvEkI9PYu+ Y04IhtvaAb3iiUQup1ArE4BlCnGSpRAIuXy+rRTGzz2kdkOysPjkEA7YbzU+HowxiB uSGwCeRLf53JYLGHH93ZHHUzqlxsWmJ9dM5M0xNw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.396
X-Spam-Level:
X-Spam-Status: No, score=-2.396 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="TmS0LSOb"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="C+XZy60j"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y-khQQI9CoN2 for <oauth@mail2.ietf.org>; Sun, 16 Aug 2026 00:56:54 -0700 (PDT)
Received: from fout-a8-smtp.messagingengine.com (fout-a8-smtp.messagingengine.com [103.168.172.151]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F19AB12A88638 for <oauth@ietf.org>; Sun, 16 Aug 2026 00:56:51 -0700 (PDT)
Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfout.phl.internal (Postfix) with ESMTP id DBBEAEC0190 for <oauth@ietf.org>; Sun, 16 Aug 2026 03:56:51 -0400 (EDT)
Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Sun, 16 Aug 2026 03:56:51 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to; s=fm1; t= 1786867011; x=1786953411; bh=fd8aWvvyafg/WkxuSim881XTXjoAn0yRBGd VR8drslQ=; b=TmS0LSObEWX36BqJvluTMJvqSgAbQkz1O7BJeF5SNSlrGq2JNHp rR0twWhr49X1iyf/kGj4f+q6nST8q9bEKllxlVOZmY3VYAuJUOtR9MK7OI6ZRhoB 7dt/J7RjiM0jn4P6x1aEVRgPJATf4IpDezG96hHIs1rFMDEaKIOKeM9H9e+SXhOX 2jurAjlfFzthbqmgFPT/ewgGi/TUG5cbvfox4NDocyGjW3Uvqon2OW9HO4y1nd6m rDV6pjazOdwcuYPhmq5G2KZHm6Ml6lE743twbiAuf0Idn95UvWD5AN7n1cWoJEAZ 0gP11VWORj6X4tHFPZRRyRG4mWq4ZZHDy2A==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1786867011; x= 1786953411; bh=fd8aWvvyafg/WkxuSim881XTXjoAn0yRBGdVR8drslQ=; b=C +XZy60j2VaACl3PZkBEpQNjnVwyGic1IaIJyRkOaOkP8a68zVCFl3gdXW7BRMnZ2 oV+Wsbdld6k0MEG0Gu3CSmePpRrrn2Jkr/BGMMemaRTrte7Ty1C9aR3e4UXA/602 D2Eqmi4csqY0W12KElkzQgO55VmoeooDKqRh4r+3qvVqUAs51rwBh4tzbGYF2X40 EzAZddQfvZI01t14jQSG56cjPzzdjzza1IIKhQDqtImtYnjQR1VqX5ub8Jb4jXT4 un1TlKe2sfnj9XKLnELYo5PAbsdmekcrW3AfH7eTXns+jk7wQOGDDDPT0qjpTF5L oHLFp8MGb7+0uU6InTMKw==
X-ME-Sender: <xms:Q22BahVspSe9aMQ-i8Wi_IZbnDKRBN7jcokmYgefcQN5wS-5HA7rEw> <xme:Q22Band0g8wpaSeUwXQEGz5ZASKeduck2ehENeX9Zb0ySiQFyKJfgJOsz6nrCZDyj oNf7SkiNitO9nsgFF4S5kpyOS2HQ1UMp__wW9RRyfXEtORtulkIOQ>
X-ME-Received: <xmr:Q22BaodNAMfzMQTIvvuQc0OSyuoCF70WJ1SmyTfYbYbPbeHG7AvW7uSeI8UmJc5-W5rHpf0rGFhH-IATdpugN1Dlm5-GPrDm3hMbKf2gJG5JickBOm9lbmdxpEe-vQ4e2ViA0v0>
X-ME-Proxy-Cause: dmFkZTErUDTXrBHCecEOHGrJ0L8Kv+lyLAtQmp0rQ1BexUzfR+13V0d+avI3QCT57qVaOn qksG+arJEGEESya6GxZmTu7LUyCzXSJAj9bx5IdfgQgUIkO+tBzkm5NszB2lX1xbLM+Ahq s4jnS+4T5914S01wWRkL4/aSdPcre/tc66SsEBpPGqfjWnYs9v3/U2QVMqcwRtrw6fyZE1 gHTprwyXkJe84YSoixAvyhmfMZcgMQNj1vvlehqtZUWKkwb4WpKNZn1tJXyM9OGW/DDMcM Um6J8mE47JUrpJ/5ZBKPw085nFjN3UtFngyzINTY1mlRMzrMSkuqUldz4pchOpc9mh8Qaj lqACAQmo2+ljd+W8Nt8ruEPhuLBaP0UPqX7dCslXrTmVBQof+3Q5fVFUEO8xhPSJjVOfGB dgusK4JZKfXHFXRBqgkxPeZpNEubiFXlpTo+0ceWtJlJxPnayEvRmY0yt7SGYo2iuM1EPY B7sH54pJgnfeQLbOOHvZeICvLrF8KxcPc+1SQwBdUA4pNrbloRvDLx3PbrM8JKXChuNJZy PDunrC43qja4w1hBR3y/JCha36tUQ0QLBIH1ejCb7ZZv1/0xCYI39aTQFB5RRs7QroLhdt wuSCdnLKwYPclUMChx57zAPlnzmMnMbwBsuTkQ/FiAT8Z/HZbOkIGS4Y+YEg
X-ME-Proxy: <xmx:Q22BahJh3DGaJC_Im4Rx403I2U6MRg1hKlWWgsY-oBbYJWBm-eFsHA> <xmx:Q22BavLrxc4xLBsmiuIWol89lNzAcwhzq5o_9AxFli6aO5gqSUBIPw> <xmx:Q22BajFjzqPhG2o5Z0njaOpkQQ9D3uGMCdayy2CVOiUh9use3YT-Gg> <xmx:Q22Bakk3T7xLFNkUVhwdKFFBuy6N5EiSY5QQyhim6oPH4mwzmUBeng> <xmx:Q22BagcZRyOcNDZ9SEQo4XwUgiWcaj2nCuEtSEQxieYp8NFw_j0373uD>
Feedback-ID: i1c3946f2:Fastmail
Message-Id: <1786867011.1625845.0A63B992@outbound.messagingengine.com>
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <oauth@ietf.org>; Sun, 16 Aug 2026 03:56:51 -0400 (EDT)
Content-Type: multipart/alternative; boundary="===============8218278481968637695=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: oauth@ietf.org
Date: Sun, 16 Aug 2026 00:56:51 -0700
Message-ID-Hash: 7WXKC72GE3ZPK4PKQ7RMV7KUUJFP6NPK
X-Message-ID-Hash: 7WXKC72GE3ZPK4PKQ7RMV7KUUJFP6NPK
X-MailFrom: do_not_reply@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Weekly github digest (OAuth Activity Summary)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/sSmZvnbWGOSR5rH8KO_Abut2UjQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>



Events without label "editorial"

Issues
------
* oauth-wg/oauth-transaction-tokens (+2/-2/šŸ’¬6)
  2 issues created:
  - transaction tokens can carry delegation and authorization information, right? Right? (by bc-pi)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/370 
  - additional context switched for transaction and request[er] context (by bc-pi)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/369 

  3 issues received 6 new comments:
  - #370 transaction tokens can carry delegation and authorization information, right? Right? (3 by PieterKas, bc-pi)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/370 
  - #369 additional context switched for transaction and request[er] context (2 by PieterKas, bc-pi)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/369 
  - #183 New Token identifier during replacement (1 by gffletch)
    https://github.com/oauth-wg/oauth-transaction-tokens/issues/183 

  2 issues closed:
  - additional context switched for transaction and request[er] context https://github.com/oauth-wg/oauth-transaction-tokens/issues/369 
  - transaction tokens can carry delegation and authorization information, right? Right? https://github.com/oauth-wg/oauth-transaction-tokens/issues/370 

* oauth-wg/oauth-sd-jwt-vc (+0/-0/šŸ’¬1)
  1 issues received 1 new comments:
  - #355 A new field called "Issuer Authorization URI - "iss_auth"" (1 by abotorabjabari)
    https://github.com/oauth-wg/oauth-sd-jwt-vc/issues/355 [pending close] [future-extension] [policy] 

* oauth-wg/oauth-v2-1 (+0/-2/šŸ’¬2)
  1 issues received 2 new comments:
  - #254 Can we add a maximum length to the `state` parameter? (2 by adeinega, fkj)
    https://github.com/oauth-wg/oauth-v2-1/issues/254 

  2 issues closed:
  - Consideration to forbid PKCE plain mode in OAuth 2.1 https://github.com/oauth-wg/oauth-v2-1/issues/236 [ietf-125] 
  - make mix-up mitigation via issuer mandatory https://github.com/oauth-wg/oauth-v2-1/issues/233 [ietf-125] 

* oauth-wg/draft-ietf-oauth-attestation-based-client-auth (+0/-0/šŸ’¬2)
  1 issues received 2 new comments:
  - #218 clarification for challenge usage needed? (2 by c2bo, mickrau)
    https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth/issues/218 

* oauth-wg/oauth-identity-assertion-authz-grant (+1/-0/šŸ’¬3)
  1 issues created:
  - add security consideration about the extra importance of validating the AS issuer URL (by aaronpk)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/122 

  2 issues received 3 new comments:
  - #122 add security consideration about the extra importance of validating the AS issuer URL (2 by KevinLuo2000, mcguinness)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/122 
  - #120 Constraints on `resource` parameter in Token Exchange (1 by mcguinness)
    https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/120 

* oauth-wg/draft-ietf-oauth-rfc8725bis (+4/-3/šŸ’¬7)
  4 issues created:
  - IESG: RECOMMENDED vs REQUIRED for typ on new JWT uses (§3.11) (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65 
  - IESG nits: inclusive language and "However" comma (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/62 
  - IESG: Appendix A item 2 points at §3.12 instead of §3.3 (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/61 
  - IESG: Justify or drop the 250 KB JWE decompression example (§3.15) (by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/60 

  3 issues received 7 new comments:
  - #65 IESG: RECOMMENDED vs REQUIRED for typ on new JWT uses (§3.11) (3 by eckelcu, selfissued)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65 
  - #61 IESG: Appendix A item 2 points at §3.12 instead of §3.3 (1 by yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/61 
  - #60 IESG: Justify or drop the 250 KB JWE decompression example (§3.15) (3 by bc-pi, yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/60 

  3 issues closed:
  - IESG: Justify or drop the 250 KB JWE decompression example (§3.15) https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/60 
  - IESG nits: inclusive language and "However" comma https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/62 
  - IESG: Appendix A item 2 points at §3.12 instead of §3.3 https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/61 

* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+3/-1/šŸ’¬7)
  3 issues created:
  - token_endpoint_auth_methods_supported  and revocation_endpoint_auth_methods_supported (by adeinega)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/96 
  - Section "4.5 Redirect URL Registration" (by adeinega)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/95 
  - jwks vs jwks_uri properties (by adeinega)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/93 

  2 issues received 7 new comments:
  - #95 Section "4.5 Redirect URL Registration" (4 by ThisIsMissEm, adeinega)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/95 
  - #87 Add `token_endpoint_auth_methods_supported` to client metadata (3 by ThisIsMissEm, aaronpk)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/87 [ietf-126] 

  1 issues closed:
  - Add `token_endpoint_auth_methods_supported` to client metadata https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/issues/87 [ietf-126] 



Pull requests
-------------
* oauth-wg/oauth-transaction-tokens (+0/-0/šŸ’¬3)
  1 pull requests received 3 new comments:
  - #371 WGLC Feedback (3 by bc-pi)
    https://github.com/oauth-wg/oauth-transaction-tokens/pull/371 

* oauth-wg/oauth-sd-jwt-vc (+3/-0/šŸ’¬0)
  3 pull requests submitted:
  -  (by bc-pi)
     
  -  (by bc-pi)
     
  -  (by danielfett)
     

* oauth-wg/oauth-v2-1 (+2/-0/šŸ’¬0)
  2 pull requests submitted:
  -  (by loganaden)
     
  -  (by loganaden)
     

* oauth-wg/oauth-identity-assertion-authz-grant (+1/-0/šŸ’¬0)
  1 pull requests submitted:
  -  (by mcguinness)
     

* oauth-wg/draft-ietf-oauth-rfc8725bis (+4/-0/šŸ’¬3)
  4 pull requests submitted:
  -  (by yaronf)
     
  -  (by yaronf)
     
  -  (by yaronf)
     
  -  (by selfissued)
     

  2 pull requests received 3 new comments:
  - #58 Made deprecate-none reference normative and rewrote "none" and RSA-PKCS1 v1.5 text accordingly (2 by selfissued, yaronf)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/58 
  - #51 SHOULD NOT to MUST NOT on JWT libraries using none without explicit instruction from caller (1 by selfissued)
    https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/pull/51 

* oauth-wg/draft-ietf-oauth-client-id-metadata-document (+1/-0/šŸ’¬1)
  1 pull requests submitted:
  -  (by adeinega)
     

  1 pull requests received 1 new comments:
  - #63 require sending Accept header when fetching metadata (1 by ThisIsMissEm)
    https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document/pull/63 [ietf-126] 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/oauth-wg/oauth-browser-based-apps
* https://github.com/oauth-wg/oauth-identity-chaining
* https://github.com/oauth-wg/oauth-transaction-tokens
* https://github.com/oauth-wg/oauth-sd-jwt-vc
* https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata
* https://github.com/oauth-wg/oauth-cross-device-security
* https://github.com/oauth-wg/oauth-selective-disclosure-jwt
* https://github.com/oauth-wg/oauth-v2-1
* https://github.com/oauth-wg/draft-ietf-oauth-status-list
* https://github.com/oauth-wg/draft-ietf-oauth-attestation-based-client-auth
* https://github.com/oauth-wg/oauth-identity-assertion-authz-grant
* https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis
* https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis
* https://github.com/oauth-wg/oauth-first-party-apps
* https://github.com/oauth-wg/draft-ietf-oauth-client-id-metadata-document


-- 
To have a summary like this sent to your list, see: https://github.com/ietf-github-services/activity-summary