oauth-wg/oauth-transaction-tokens

Clarification on additional signatures

dteleguin opened this issue · 1 comments

From 2.4. Benefits of Txn-Tokens:

Through the presence of additional signatures on the Txn-Token, a workload receiving an invocation can also independently verify that specific workloads were within the path of the call before it was invoked.

It is unclear from the document how exactly the additional signatures could be added to the Txn-Token by the workloads within the call chain. Would be nice to provide some details here, or to state that this is out of the scope of the current document.

this issue is outdated. It seems to have been addressed in the new draft.