Skip to content

ARAP: make example binding artifacts conform to the profile - #690

Open
vatsalgupta wants to merge 1 commit into
openid:mainfrom
vatsalgupta:arap-example-binding-artifacts
Open

vatsalgupta wants to merge 1 commit into
openid:mainfrom
vatsalgupta:arap-example-binding-artifacts

Conversation

@vatsalgupta

Copy link
Copy Markdown

This is the editor task from #660. The example tokens were not valid under the profile.

Problem

  • Each example binding_token held only an evaluation_id. It had no aud, so a conforming Access Request Service would have to reject it.
  • The example approval.state values had no iss or aud.
  • In the Callback example, approval.state expired at 17:00 but approved_until was 17:30.

Change

  • Replaced all 13 example tokens (base profile and the four companions) with real signed ES256 tokens.
  • Each binding_hash is computed with the Hash Construction section over that example's submission.
  • Fixed the Callback expiry.

Notes

I checked all 13 against the verification steps in the text. The keys are throwaway. The public keys are below if anyone wants to check.

Example JWK Set
{
  "keys": [
    {
      "kty": "EC",
      "crv": "P-256",
      "kid": "pdp-1",
      "use": "sig",
      "alg": "ES256",
      "x": "qKRYVWkmMg8XhEVJwcgkdLsDuM4MgzDtM4H0eTkpOOo",
      "y": "ZVqOEQYtNr0Ip6wJV4Gj-gP2G-DHRxONoWhFzLIj6Jk"
    },
    {
      "kty": "EC",
      "crv": "P-256",
      "kid": "ars-1",
      "use": "sig",
      "alg": "ES256",
      "x": "qEkmS8NSDNjRoS6KONu-jweL79joBNZGX0XAYf5Ahb4",
      "y": "jHOLMTAMS8qTjoSAIS6l-vlTcOxD34G1CsVyoRtLyX8"
    }
  ]
}

Refs #660

Every example binding_token decoded to correlation data only, with no
aud (which a conforming Access Request Service must reject), no iss or
exp, and no binding material, so none illustrated the self-contained
token the independent-service requirement calls for.  The example
approval.state values lacked the aud and iss the Approval State section
requires.

Replace all 13 example artifacts across the base profile and the four
companions with ES256 JWS values that:

* carry iss, aud, iat, exp, jti, evaluation_id, denial_expires_at,
  binding_context_members, and binding_hash for denial binding;
* use the hashed form, since the inline claim names are not yet defined
  (openid#660);
* compute binding_hash with the exact construction in Hash Construction
  (and the bulk construction in the Bulk profile) over each example's
  submitted tuple;
* carry iss, aud, exp, approval_id, and binding_context_members for
  approval.state, with exp no later than approved_until.

The Callback profile's approval.state previously expired at 17:00 while
approved_until was 17:30; the new value expires with the approval.

Deployment-specific claims already present (class, scope, bundle_id)
are kept.  Issuer and audience values use the policy_decision_point
and access_request_endpoint URLs from the PDP metadata example, pending
openid#661.

No normative text changes.

Refs openid#660

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant