openid / openid/authzen

decision_ref binding: pin to binding_token now, or track ARAP as published?

Open
#606 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

access-requests
Dominant language
TypeScript
Stars
160
Forks
41
Avg merge
2d 3h
Merged PRs (30d)
23

Description

@mcguinness #532 would make binding_token REQUIRED for an independent ARS, ending the evaluation_id / binding_token symmetry in decision_ref. It has been open since 13 July.

I am writing a subject-side profile against ARAP and need to know which way to write it: pin to binding_token now, or follow ARAP as published and revise if #532 lands?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading issue #532 and the published ARAP material referenced in the issue. Compare the two possible decision_ref approaches for the subject-side profile, then confirm which direction maintainers want. Done means the profile guidance has a settled, documented choice or an explicit plan for revising it.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.