I-D Action: draft-zehavi-oauth-authz-req-del-chain-00.txt
[email protected] Fri, 07 Aug 2026 06:22:09 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178610892902.489.490277576003786939@dt-datatracker-559c48c7fb-llb9x> |
Internet-Draft draft-zehavi-oauth-authz-req-del-chain-00.txt is now available. Title: OAuth Authorization Request Delegation Chain Author: Yaron Zehavi Name: draft-zehavi-oauth-authz-req-del-chain-00.txt Pages: 35 Dates: 2026-08-07 Abstract: Brokered OAuth redirect authorization requests involve intermediary authorization servers between a downstream client and the upstream authorization server that obtains user consent and issues tokens. Such deployments have security risks because the upstream authorization server sees only the immediate OAuth client and is unaware of the downstream client or intermediary brokers obtaining its response. This document defines an informative OAuth 2.0 profile for carrying a verifiable, signed authorization request delegation chain as a RAR authorization_details object [RFC9396]. Each node in the chain is a JSON object signed by the attesting authorization server or broker using detached JWS [RFC7515], attesting its validated client, hash- linked to the previous node, allowing the upstream authorization server to validate the exact delegation path before issuing tokens. This document does not define new OAuth endpoints, grant types, error codes, token formats, token response parameters, or token request parameters. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-zehavi-oauth-authz-req-del-chain/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-zehavi-oauth-authz-req-del-chain-00.html Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]