Clients should be required to support `need_info` section of UMA2 to better meet authorization goals
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Domain
- authentication, authorization
Research direction
Start with Solid-OIDC draft section 9.1 and the UMA2 references linked in the issue, then review the discussion in #158. Compare the server recommendation with UMA2 client interaction requirements, especially need_info. Done means reaching a clear normative decision and identifying the corresponding specification text to change.
Written by the indexing model from the issue text.
Description
As per the current Solid-OIDC draft sec 9.1:
Authorization Servers SHOULD implement User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorization [UMA].
However, there's no equivalent of
clients MUST (SHOULD?) have support for UMA2 interaction workflows
If the client doesn't understand UMA2 (in particular, need_info etc), the client wouldn't be able to fulfil UMA2's authorization requirements, culminating in a 401/403. Or am I reading UMA2 specs incorrectly?
This puts the Pod Provider in a spot. One can easily see the users complain that (non-UMA2) clients work with other pod providers, but not this server (which supports UMA2). This disincentivizes pod providers to support UMA2, while placing no incentives for clients to support it.
Given that Solid-OIDC concerns itself only with authentication, and not authorization, as stated by @acoburn in #158, the recommendation for servers to support UMA2 seems either out of place, or should be done only in conjunction with requiring clients to support UMA2. Personally, I'd prefer the latter.
- Dominant language
- Bikeshed
- Stars
- 26
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from solid/solid-oidc
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
solid/solid-oidc#258 ·
-
doc: solid-oidc-primer editorial
Difficulty 1/5 Under an hour Newbie friendliness 75/100
solid/solid-oidc#144 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 20/100
solid/solid-oidc#238 · 1 comment ·
-
Difficulty 5/5 Over a week Newbie friendliness 15/100
solid/solid-oidc#237 · 1 comment · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
solid/solid-oidc#231 · 1 comment ·
All issues in solid/solid-oidc
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
AXERA-TECH/ax-llm#75 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gitbutlerapp/gitbutler#15998 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security impact:ux-friction issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
TheManticoreProject/Manticore#1383 ·