Skip to content

SEP-2468: add Authorization spec changes for RFC 9207 iss validation - #2646

Merged
pcarleton merged 9 commits into
sep-issuer-claim-authfrom
paulc/sep-2468-authorization-spec
Apr 24, 2026
Merged

pcarleton merged 9 commits into
sep-issuer-claim-authfrom
paulc/sep-2468-authorization-spec

Conversation

@pcarleton

Copy link
Copy Markdown
Member

Stacked on #2468. For review before merging into that PR's branch.

docs/specification/draft/basic/authorization.mdx:

  • Adds RFC 9207 to Standards Compliance
  • Updates the flow diagram (record expected issuer before redirect; validate iss on callback)
  • New Authorization Response Validation subsection with the metadata-keyed decision table. Row 3 (not advertised + iss present) deliberately compares rather than rejects, which is more lenient than RFC 9207 §2.4, to accommodate ASes that emit iss without advertising it yet.
  • New Mix-Up Attacks entry under Security Considerations

seps/2468-recommend-issuer-claim-for-auth.md:

  • Security Implications → links RFC 9207 §4, drops TODO
  • Reference Implementation → links go-sdk#859 and typescript-sdk#1957
  • Acknowledgments → WG participants

Reference implementations:

Adds Authorization Response Validation subsection with the metadata-keyed
decision table, updates the flow diagram, lists RFC 9207 under Standards
Compliance, and adds a Mix-Up Attacks entry under Security Considerations.
@pcarleton
pcarleton requested a review from a team as a code owner April 24, 2026 15:22
@pcarleton
pcarleton requested a review from a team as a code owner April 24, 2026 15:37
The @-handle regex was matching inside email addresses (e.g.,
@microsoft in <[email protected]>), and angle-bracket emails then
broke MDX parsing. Now converts <email> to (email) and only links
@handle when not part of an email.
render-seps.ts auto-links @-handles in author lines to GitHub. With an
email present it matches the domain (e.g., @microsoft in
<[email protected]>), and the surrounding angle brackets then break
MDX parsing in the generated docs/seps page (mint sees `<user[` as a
malformed JSX tag). The previous commit fixed the regex; this commit
reverts that and instead drops the email so the existing simple regex
works. SEP-1034 has the same latent issue ([email protected] links
to github.com/gmail) but is non-blocking and out of scope here.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant