KantaraInitiative/wg-uma
This is the repository of all specifications related to the User Managed Access Group
XSLTNOASSERTION
Issues
- 3
Returning RPT from Resource Server
#355 opened by pedroigor - 2
register the "UMA" auth scheme with IANA
#362 opened by xmlgrrl - 3
Scope of Current Extension Effort
#364 opened by aleclaws - 0
Need to edit Grant and FedAuthz specs to reflect that OAuth AS metadata spec is final
#361 opened by xmlgrrl - 0
Typo in Grant 2.0
#360 opened by xmlgrrl - 4
Comments received during AMB
#359 opened by xmlgrrl - 5
- 0
Add request_submitted code example
#356 opened by xmlgrrl - 0
Remove set math parenthetical clarification
#357 opened by xmlgrrl - 16
No error for bad request body in FedAuthz RReg
#354 opened by mrpotes - 5
- 3
Which error code to return when candidate granted scopes is less than requested scopes
#350 opened by joebandenburg - 5
Terminology and diagram comments
#335 opened by xmlgrrl - 15
Variety of issues on revs 05
#337 opened by xmlgrrl - 13
No error defined for policy evaluation failed
#340 opened by mrpotes - 1
Security considerations could be made clearer
#342 opened by mrpotes - 10
- 6
No means no! (Alice's right to revoke)
#348 opened by mrpotes - 4
Why is PAT used for ticket and introspection?
#352 opened by mrpotes - 5
Editorial issues on FedAuthz from Cigdem
#351 opened by xmlgrrl - 3
- 3
Behaviour for bad claim_token_format values
#345 opened by mrpotes - 3
Behaviour for invalid/expired claim_token
#344 opened by mrpotes - 3
Token error response should defer to 6749
#343 opened by mrpotes - 5
- 1
Permission endpoint request implies array cannot be used for single resource identifier
#339 opened by mrpotes - 1
- 0
Make the permission ticket optional when "upgrading" the RPT for an UMA-native refresh flow
#353 opened by xmlgrrl - 0
- 4
- 2
FedAuthz Sec 9.2 should reference RFC 7519 as JWT Registry basis, not OIDCCore
#330 opened by xmlgrrl - 2
Registration request for JWT permissions claims incomplete and may have other issues
#334 opened by xmlgrrl - 3
How are client-contributed scopes mapped to resources during authorization assessment?
#328 opened by xmlgrrl - 0
- 1
- 1
- 6
An array of (what)
#327 opened by xmlgrrl - 0
Definition of permission ticket
#326 opened by xmlgrrl - 8
Editorial items from Justin
#323 opened by xmlgrrl - 1
- 3
Need a security consideration for the state parameter
#316 opened by xmlgrrl - 2
Human-readable scope display should be explicit
#320 opened by xmlgrrl - 1
- 2
Errors are ill-defined
#321 opened by xmlgrrl - 1
- 2
Possible to get an RPT for a resource with no scopes?
#317 opened by xmlgrrl - 3
Say what happens when claims_redirect_uri is missing
#315 opened by xmlgrrl - 2
Correct rpt description
#314 opened by xmlgrrl - 3
- 2