Skip to content
This repository was archived by the owner on Apr 13, 2022. It is now read-only.

Conversation

@michielbdejong
Copy link

Creating this as a placeholder, it's still incomplete in several aspects:

This is something we're experimenting with in IPS and that shouldn't be merged unless/until NSS also implements it.

Creating this as a placeholder, it's still incomplete in several aspects:
* we should mention somewhere why PoP token issuer is better than Origin header (namely because of solid/web-access-control-spec#34)
* we should mention that a PoP token is only valid if the issuer is listed in the id token's audiences (is this something the IDP checks and then signs for? I don't even know)
@kjetilk kjetilk added the proposed-spec-change May or may not be adopted in future spec versions. Experimental; not yet universally supported. label Jun 18, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

proposed-spec-change May or may not be adopted in future spec versions. Experimental; not yet universally supported.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants