Re: [OAUTH-WG] [EXTERNAL] Re: JWT Secured Authorization Request (JAR) vs OIDC request object

2020-01-18 Thread Neil Madden
On 17 Jan 2020, at 03:58, Benjamin Kaduk wrote: > > On Thu, Jan 16, 2020 at 04:31:30PM +, Neil Madden wrote: >> The mitigations of 10.4.1 are related, but the section heading is about >> (D)DoS attacks. I think this heading needs to be reworded to apply to SSRF >> attacks too or else add an

[OAUTH-WG] Adam Roach's No Objection on draft-ietf-oauth-jwt-introspection-response-08: (with COMMENT)

2020-01-18 Thread Adam Roach via Datatracker
Adam Roach has entered the following ballot position for draft-ietf-oauth-jwt-introspection-response-08: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Pl