Markdown Version | Recording 1 | Recording 2

Session Date/Time: 07 Nov 2022 09:30

oauth

Summary

The OAuth working group session covered updates on several active drafts, including OAuth 2.1, Browser-Based Apps, SD-JWT, Step-Up Authentication, and a new proposal for Interactive Authentication. Key discussions revolved around consolidating best practices into OAuth 2.1, managing CORS behavior for various OAuth endpoints, refining token storage recommendations for browser applications, addressing encoding and algorithm agility in SD-JWT, and exploring challenges in standardizing interactive authentication for non-web HTTP clients. Several action items and decisions were made regarding the direction and required clarity for these specifications.

Key Discussion Points

Decisions and Action Items

Next Steps


Session Date/Time: 09 Nov 2022 13:00

oauth

Summary

The oauth session covered three key topics: an update on JOT Embedded Tokens, a discussion on the proposed charter for fine-grained transactional authorization, and an in-depth presentation on cross-device flows and client ID for anonymous clients. Discussions centered on proposed architectural changes, security implications, and potential new work items for the working group. The chairs announced a call for adoption for the cross-device flows document.

Key Discussion Points

JOT Embedded Tokens (formerly Multiple Subject JOT)

Fine-Grained Transactional Authorization

Cross Device Flows

Client ID for Anonymous Clients

Decisions and Action Items

Next Steps