Update to DPoP specification v08
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- authentication, documentation, security
Research direction
Read the DPoP-related parts of the specification and the primer first, then compare their links and guidance with draft-ietf-oauth-dpop-08. Update the relevant text and links to cover dpop_jkt, server-provided nonces, and the treatment of dpop_bound_access_tokens; done means the spec and primer consistently reflect v08.
Written by the indexing model from the issue text.
Description
Recent DPoP spec updates introduce some changes that could be relevant for Solid-OIDC. I'd suggest that we update the DPoP-related parts of the spec and the primer in order to reflect those changes (most importantly server-supplied nonces); the links should be updated to -08 as well.
dpop_jkt request parameter
This parameter could be used to enforce end-to-end binding (from authorization code to the resulting tokens). See 10. Authorization Code Binding to DPoP Key
Use of this parameter is OPTIONAL.
Server-provided nonces
The concept of server-provided nonces is introduced as an alternate (and potentially more efficient) mechanism to limit the lifetime of DPoP proofs. See 8. Authorization Server-Provided Nonce
It's up to the authorization server implementation whether to support nonces, but the client support is MANDATORY; otherwise the client simply won't be able to talk to the server that employs nonces. The same is valid for the resource server supplied nonces (Section 9).
dpop_bound_access_tokens client registration parameter
As we're relying on DPoP-bound ID tokens (rather than access tokens) and we're using scope="... webid" to indicate this (see #168), the use of dpop_bound_access_tokens client registration parameter is not necessary.
- Dominant language
- Bikeshed
- Stars
- 26
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from solid/solid-oidc
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
solid/solid-oidc#258 ·
-
doc: solid-oidc-primer editorial
Difficulty 1/5 Under an hour Newbie friendliness 75/100
solid/solid-oidc#144 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 20/100
solid/solid-oidc#238 · 1 comment ·
-
Difficulty 5/5 Over a week Newbie friendliness 15/100
solid/solid-oidc#237 · 1 comment · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
solid/solid-oidc#231 · 1 comment ·
All issues in solid/solid-oidc
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
AXERA-TECH/ax-llm#75 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gitbutlerapp/gitbutler#15998 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security impact:ux-friction issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
TheManticoreProject/Manticore#1383 ·