Re: [OAUTH-WG] [EXTERNAL] Re: JWT Secured Authorization Request (JAR) vs OIDC request object

2020-01-14 Thread Takahiko Kawasaki
Well, embedding a client_id claim in the JWE header in order to achieve "request parameters outside the request object should not be referred to" is like "putting the cart before the horse". Why do we have to avoid using the traditional client_id request parameter so stubbornly? The last paragraph

[OAUTH-WG] JWT Secured Authorization Request (JAR): signing

2020-01-14 Thread George Aristy
Hello everyone. Is it possible to relax the requirement to sign the claims set if an authenticated encryption mode with prior shared secrets is used? Eg. https://tools.ietf.org/html/draft-madden-jose-ecdh-1pu-02. This would reduce the size of the request object substantially. Regards, George Aris