Consider adding a unique token identifier to Session Established CAEP Events
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 65/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Domain
- documentation
Research direction
Start with section 3.6, especially sections 3.6.1 and 3.6.2 of the linked CAEP specification, and compare the current Session Established claims and example. Update the specification to describe the proposed unique token identifier for SAML assertions and OIDC tokens, then revise the example event accordingly.
Written by the indexing model from the issue text.
Description
Current State: There is no current way to correlate the SAML assertion or OIDC token that was issued by the IdP and the corresponding RP session that was established as described below:
Currently, the only correlation claim can be ext_id that provides the RP session identifier, but it does not provide the exact token or assertion identifier that establishes that session.
Proposal: Update section 3.6.1 to introduce the additional proposed claim to capture a unique token identifier, id for SAML assertion and jti for OIDC token, and update the example event on section 3.6.2. The proposed claim may be used by the IdP to detect token replays on the RP and / or further analysis.
- Dominant language
- Makefile
- Stars
- 78
- Forks
- 18
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/sharedsignals
-
Workload identity
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
openid/sharedsignals#345 · 1 comment ·
-
certlaunchv1
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
openid/sharedsignals#341 ·
-
future spec:SSF
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
openid/sharedsignals#340 · 1 comment ·
-
certlaunchv1 spec:Interop
Difficulty 5/5 Over a week Newbie friendliness 35/100
openid/sharedsignals#351 · 4 comments ·
-
certlaunchv1 spec:Interop
Difficulty 5/5 Over a week Newbie friendliness 35/100
openid/sharedsignals#350 · 2 comments · 2 reactions ·
All issues in openid/sharedsignals
Similar issues
-
user-reported
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Kong/developer.konghq.com#7316 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
bug triage:deciding
Difficulty 1/5 Under an hour Newbie friendliness 88/100
open-telemetry/otel-arrow#4132 ·
-
Ecosystem: ClawMetry — the Qwen Code reader is now free and open source (follow-up to #9294 / #9338) Opencategory/integration priority/P3 scope/documentation status/ready-for-human type/feature-request
Difficulty 1/5 Under an hour Newbie friendliness 84/100