self-contained token - cover sub claim #2406
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
V3
V51
Group issues related to OAuth
_5.0 - prep
This needs to be addressed to prepare 5.0
Spin-off from #1967, Post by TobiasAhnoff from #1967 (comment):
As far as I can tell this is all covered by other 3.5 requirements, except for 'sub', which covered by
Perhaps it would make sense to have a requirement in 3.5 for "sub", perhaps change 3.5.6 to only address "sub"?
(this is from https://www.rfc-editor.org/rfc/rfc8725.html#section-3.8)
This is basically the same as 2.11.1, but 2.11.1 is focused on IdP and users (not users and clients, consumers) and 51.4.4 has OAuth details, so maybe all three are needed?
The text was updated successfully, but these errors were encountered: