oauth-wg/oauth-transaction-tokens

Clarify `sub` field

Closed this issue · 1 comments

From Yaron's feedback email:
sub" should be better clarified, this is not your typical “sub”. Also, I strongly prefer "sub_id" here (RFC 9493), as the use case I have an mind is of the subject as a human. In addition, "as defined by the aud trust domain" is confusing, I think you want to say that "sub" is relative to the scope of the trust domain.

Editors feels that the sub format is more appropriate for TraTs. Please reopen if you would like to discuss.