{"id":2152,"date":"2021-03-19T13:38:09","date_gmt":"2021-03-19T20:38:09","guid":{"rendered":"https:\/\/self-issued.info\/?p=2152"},"modified":"2021-03-19T13:38:09","modified_gmt":"2021-03-19T20:38:09","slug":"oauth-2-0-jwt-secured-authorization-request-jar-updates-addressing-remaining-review-comments","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2152","title":{"rendered":"OAuth 2.0 JWT Secured Authorization Request (JAR) updates addressing remaining review comments"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" alt=\"OAuth logo\" src=\"https:\/\/self-issued.info\/images\/oauth_logo_120x120.png\"><\/span>After the <b>OAuth 2.0 JWT Secured Authorization Request (JAR)<\/b> specification <a href=\"https:\/\/self-issued.info\/?p=2121\">was sent to the RFC Editor<\/a>, the IESG requested an additional round of IETF feedback.  We&#8217;ve published an updated draft addressing the remaining review comments, specifically, SecDir comments from Watson Ladd.  The only normative change made since the 28 was to change the MIME Type from &#8220;<code>oauth.authz.req+jwt<\/code>&#8221; to &#8220;<code>oauth-authz-req+jwt<\/code>&#8220;, per advice from the designated experts.<\/p>\n<p>As a reminder, this specification takes the JWT Request Object from <a href=\"https:\/\/openid.net\/specs\/openid-connect-core-1_0.html#JWTRequests\">Section 6 of <b>OpenID Connect Core<\/b> (<i>Passing Request Parameters as JWTs<\/i>)<\/a> and makes this functionality available for pure OAuth 2.0 applications &#8212; and does so without introducing breaking changes.  This is one of a series of specifications bringing functionality originally developed for OpenID Connect to the OAuth 2.0 ecosystem.  Other such specifications included <b>OAuth 2.0 Dynamic Client Registration Protocol<\/b> [<a href=\"https:\/\/tools.ietf.org\/html\/rfc7591\">RFC 7591<\/a>] and <b>OAuth 2.0 Authorization Server Metadata<\/b> [<a href=\"https:\/\/tools.ietf.org\/html\/rfc8414\">RFC 8414<\/a>].<\/p>\n<p>The specification is available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-jwsreq-31\">https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-jwsreq-31<\/a><\/li>\n<\/ul>\n<p>An HTML-formatted version is also available at:<\/p>\n<ul>\n<li><a href=\"https:\/\/self-issued.info\/docs\/draft-ietf-oauth-jwsreq-31.html\">https:\/\/self-issued.info\/docs\/draft-ietf-oauth-jwsreq-31.html<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>After the OAuth 2.0 JWT Secured Authorization Request (JAR) specification was sent to the RFC Editor, the IESG requested an additional round of IETF feedback. We&#8217;ve published an updated draft addressing the remaining review comments, specifically, SecDir comments from Watson Ladd. The only normative change made since the 28 was to change the MIME Type [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,32,27,26,14,25],"tags":[],"class_list":["post-2152","post","type-post","status-publish","format-standard","hentry","category-claims","category-ietf","category-json","category-oauth","category-openid","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2152"}],"version-history":[{"count":1,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2152\/revisions"}],"predecessor-version":[{"id":2153,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2152\/revisions\/2153"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}