OAuth 2.0 Protected Resource Metadata for the Credential Issuer?
Open
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 125
- Forks
- 41
- PR merge metrics
- No merged PRs in 30d
Description
I was wondering if it would make sense to state optionally that credential issuer may advertise OAuth 2.0 Protected Resource Metadata, in addition to credential issuer metadata.
- In VCI
scopeis an optional attribute of acredential_configuration. If not provided, the wallet has a single - implied -option to useauthorization_details, in authorization code grant. Resource metadata would allow the issuer to explicitly define this. - In VCI there is no option for the credential issuer to express
DPoPrequirements (required or not, supporter algorithms, DPoP Nonce etc).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the VCI sections covering credential configuration, scope, authorization_details, and credential issuer metadata, then compare the linked OAuth 2.0 Protected Resource Metadata draft and its DPoP provisions. Done would require a resolved specification decision and corresponding updates to the VCI metadata requirements; no repository files or tests are named.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100