Clarify in the Primer whether access tokens are DPoP-bound
Open
Nobody has claimed this yet.
doc: solid-oidc-primer
- Dominant language
- Bikeshed
- Stars
- 26
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
In step 13 of the Primer, the resulting access token is a plain Bearer token. It would be helpful to clarify whether this token may, should or should not be a DPoP-bound access token.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with step 13 of the Primer and review the surrounding request flow and the repository's authentication specification guidance. Determine whether the resulting access token may, should, or should not be DPoP-bound. Done means the Primer explicitly answers that question in step 13.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100