|
1 | 1 | {
|
2 | 2 | "magic": "E!vIA5L86J2I",
|
3 |
| - "timestamp": "2025-07-15T00:21:26.621663+00:00", |
| 3 | + "timestamp": "2025-07-17T00:21:24.047194+00:00", |
4 | 4 | "repo": "oauth-wg/draft-ietf-oauth-status-list",
|
5 | 5 | "labels": [
|
6 | 6 | {
|
|
5902 | 5902 | "state": "OPEN",
|
5903 | 5903 | "author": "adeinega",
|
5904 | 5904 | "authorAssociation": "NONE",
|
5905 |
| - "assignees": [], |
| 5905 | + "assignees": [ |
| 5906 | + "tplooker" |
| 5907 | + ], |
5906 | 5908 | "labels": [],
|
5907 | 5909 | "body": "Property `uri` is currently defined as\n\n`The uri (URI) claim MUST specify a String value that identifies the Status List Token containing the status information for the Referenced Token. The value of uri MUST be a URI conforming to [RFC3986].`\n\nThe issue here is that an issuer of ATs can and query and path parameters (unique to each issued AT), that would allow to track the usage of ATs. While it's technically impossible to completely \"hide\" information about who downloaded the status list (I refer to SRC IP, user's agent, etc.), the spec in my view should discourage, and even explicitly forbid such techniques. Otherwise, it leaves the door open for this sort of misuse... which also defects the purpose of being a privacy-preserving way to check the statuses of tokens.\n\nI also think it's a bit better to refer to `uri` as one of properties of the `status` claim, not as `claim`.",
|
5908 | 5910 | "createdAt": "2025-07-10T03:46:45Z",
|
5909 |
| - "updatedAt": "2025-07-14T16:09:33Z", |
| 5911 | + "updatedAt": "2025-07-16T06:24:22Z", |
5910 | 5912 | "closedAt": null,
|
5911 | 5913 | "comments": [
|
5912 | 5914 | {
|
|
5915 | 5917 | "body": "There is a bit text on the danger of malicious issuers here: https://drafts.oauth.net/draft-ietf-oauth-status-list/draft-ietf-oauth-status-list.html#name-malicious-issuers. Nonetheless, I agree that it would probably be a good idea to add a bit of text that using path/query parameters is not permitted for the URI that is included in the token.",
|
5916 | 5918 | "createdAt": "2025-07-14T16:09:33Z",
|
5917 | 5919 | "updatedAt": "2025-07-14T16:09:33Z"
|
| 5920 | + }, |
| 5921 | + { |
| 5922 | + "author": "paulbastian", |
| 5923 | + "authorAssociation": "CONTRIBUTOR", |
| 5924 | + "body": "Agree with Christian, we already have some text, but it could be enhanced with the given context.", |
| 5925 | + "createdAt": "2025-07-15T23:23:31Z", |
| 5926 | + "updatedAt": "2025-07-15T23:23:31Z" |
5918 | 5927 | }
|
5919 | 5928 | ]
|
5920 | 5929 | }
|
|
19723 | 19732 | "labels": [],
|
19724 | 19733 | "body": "",
|
19725 | 19734 | "createdAt": "2025-07-09T21:33:07Z",
|
19726 |
| - "updatedAt": "2025-07-10T03:12:46Z", |
| 19735 | + "updatedAt": "2025-07-16T06:22:03Z", |
19727 | 19736 | "baseRepository": "oauth-wg/draft-ietf-oauth-status-list",
|
19728 | 19737 | "baseRefName": "main",
|
19729 | 19738 | "baseRefOid": "c50a2fab7e0ddaa6fea8996c01de525b10d98674",
|
|
19755 | 19764 | "updatedAt": "2025-07-09T22:56:47Z"
|
19756 | 19765 | }
|
19757 | 19766 | ]
|
| 19767 | + }, |
| 19768 | + { |
| 19769 | + "id": "PRR_kwDOJZ2aqs60NFAk", |
| 19770 | + "commit": { |
| 19771 | + "abbreviatedOid": "fb79496" |
| 19772 | + }, |
| 19773 | + "author": "tplooker", |
| 19774 | + "authorAssociation": "COLLABORATOR", |
| 19775 | + "state": "APPROVED", |
| 19776 | + "body": "", |
| 19777 | + "createdAt": "2025-07-16T06:21:37Z", |
| 19778 | + "updatedAt": "2025-07-16T06:21:37Z", |
| 19779 | + "comments": [] |
| 19780 | + }, |
| 19781 | + { |
| 19782 | + "id": "PRR_kwDOJZ2aqs60NFiI", |
| 19783 | + "commit": { |
| 19784 | + "abbreviatedOid": "fb79496" |
| 19785 | + }, |
| 19786 | + "author": "c2bo", |
| 19787 | + "authorAssociation": "MEMBER", |
| 19788 | + "state": "APPROVED", |
| 19789 | + "body": "", |
| 19790 | + "createdAt": "2025-07-16T06:22:03Z", |
| 19791 | + "updatedAt": "2025-07-16T06:22:03Z", |
| 19792 | + "comments": [] |
19758 | 19793 | }
|
19759 | 19794 | ]
|
19760 | 19795 | }
|
|
0 commit comments