Use of Interactive Authorization Endpoint in the context of split-architecture implementation.
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 125
- Forks
- 41
- PR merge metrics
- No merged PRs in 30d
Description
During the workgroup meeting this morning we spent some time discussing the privacy and security implications when using the Interactive Authorization Endpoint in a split-architecture implementation as described in #605 .
Depending on the type of request made, there can be privacy reasons for the server not being able to see the request made. Possible ways to achieve this could be either contacting the IAE endpoint directly or encrypting the request to the device, but there may be other means.
One thing to consider in that context is whether #623 could negatively impact what's possible from a privacy perspective in a split-architecture model.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading issues #605 and #623, then review the discussion around the Interactive Authorization Endpoint and split-architecture implementation. Done would require an agreed approach or documented decision addressing whether the server can be prevented from seeing requests and whether #623 affects that privacy model.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100