Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request #136

Open
jbman opened this issue Oct 14, 2021 · 3 comments
Assignees
Labels
2.0 Work related to 2.0 release enhancement New feature or request pinned Pinned item, won't become stale

Comments

@jbman
Copy link

jbman commented Oct 14, 2021

In the current protocol the OP is required to provide an unspecified endpoint for managing request configurations
(see https://github.com/bcgov/vc-authn-oidc/blob/master/docs/README.md#vc-presentation-request-configuration).
This could be refined based on Pushed Authorization Requests so that management of this request configuration is well-defined.

@jbman jbman changed the title VC Presentation Request Configuration could rather be be an OAuth2 Pushed Authorization Request VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request Oct 14, 2021
@esune esune added the enhancement New feature or request label Oct 14, 2021
@esune
Copy link
Member

esune commented Oct 14, 2021

Thank you for the links. I see the spec is still in draft, so it might be wise to wait until it is formalized to implement it, but it looks like a good path moving forward. Currently, the endpoint is well defined, but having an arbitrary pres_req_conf_id in the query parameters is definitely not ideal from a security standpoint - this is why the system requesting authentication MUST check for a matching pres_req_conf_id value in the JWT received in the response (see here).

If you have time to put together a PR we would be happy to review and evaluate it 🙂

@esune esune added the 2.0 Work related to 2.0 release label Jan 19, 2023
@stale
Copy link

stale bot commented Mar 20, 2023

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the stale label Mar 20, 2023
@esune esune added pinned Pinned item, won't become stale and removed stale labels Mar 20, 2023
@esune
Copy link
Member

esune commented Mar 20, 2023

Pinning issue for re-assessment.

@hiteshgh hiteshgh changed the title VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request SPIKE- VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request Jun 6, 2023
@hiteshgh hiteshgh changed the title SPIKE- VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request VC Presentation Request Configuration could rather be an OAuth2 Pushed Authorization Request Jun 6, 2023
@esune esune self-assigned this Jun 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2.0 Work related to 2.0 release enhancement New feature or request pinned Pinned item, won't become stale
Projects
None yet
Development

No branches or pull requests

2 participants