spring-projects / spring-projects/spring-security
Support RFC 9493 ("sub_id" claim)
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Expected Behavior
RFC 9493 defines the "sub_id" claim for transmitting typed subject identifiers, rather than relying on the flat string of "sub".
Support for this at the Resource and Authorization servers would be very helpful, similar to the SAML ID support.
Current Behavior
Manually parsing and serialising the structures and string constants from/to the Map<String, Object> of claims.
Context
Identifying users that may have multiple identifiers, federating across domains that may have identifier conflicts, etc.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading RFC 9493, then locate how Resource and Authorization servers handle claims in Map<String, Object> and compare that path with the existing SAML ID support. The work is complete when the typed sub_id claim can be supported without manual parsing and serialization of its structures and string constants.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100