Skip to content

ARAP: carry authorization-relevant Context in the re-evaluation example - #691

Open
vatsalgupta wants to merge 1 commit into
openid:mainfrom
vatsalgupta:arap-reevaluation-example-context
Open

vatsalgupta wants to merge 1 commit into
openid:mainfrom
vatsalgupta:arap-reevaluation-example-context

Conversation

@vatsalgupta

Copy link
Copy Markdown

The submission example states that project was authorization-relevant in the original evaluation and preserves it. The re-evaluation example for the same Subject, Resource, Action, and approval sends only time and approval, so a PEP following it would fail the exact-match approval-scope comparison with out_of_scope.

This links the re-evaluation example to the submission example and includes project in its Context.

No normative text changes. The rule that the PEP resends the original Context is left to #663.

Refs #663

The submission example states that `project` was authorization-relevant
in the original evaluation and preserves it.  The re-evaluation example
for the same Subject, Resource, Action, and approval sent only `time`
and `approval`, so a PEP following it would fail the exact-match
approval-scope comparison with `out_of_scope`.

Link the re-evaluation example to the submission example and include
`project` in its Context.  No normative text changes; the rule that the
PEP resends the original Context is left to openid#663.

Refs openid#663

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant