solid / solid/solid-oidc

Clarify in the Primer whether access tokens are DPoP-bound

Open
#213 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

doc: solid-oidc-primer
Dominant language
Bikeshed
Stars
26
Forks
14
PR merge metrics
No merged PRs in 30d

Description

In step 13 of the Primer, the resulting access token is a plain Bearer token. It would be helpful to clarify whether this token may, should or should not be a DPoP-bound access token.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with step 13 of the Primer and review the surrounding request flow and the repository's authentication specification guidance. Determine whether the resulting access token may, should, or should not be DPoP-bound. Done means the Primer explicitly answers that question in step 13.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.