WLCG-AuthZ-WG/common-jwt-profile

Use RFC 9068 for token version

Opened this issue · 4 comments

hshort commented

Apparently RFC 9068 uses the standard JWT typ claim to identify the token version/type. It would be better to use this than our own "wlcg.ver" claim. This was raised by @jbasney

msalle commented

better groups then: https://www.rfc-editor.org/rfc/rfc9068.html#section-2.2.3.1
But Brian has brought that up previously AFAIR

The "groups" syntax in their example looks usable, AFAICS:

https://www.rfc-editor.org/rfc/rfc7643#section-8.2