Repository navigation
AAuth draft-11 migration and compliance remediation - #51
Merged
Merged
Conversation
- Pin the unpublished specification and companion snapshots. - Map SDK, API, sample and documentation changes. - Record migration gates and source-linked questions for upstream. 📚 - Generated by Copilot
📚 - Generated by Copilot
…o -11 - Introduced new files for updating Person Server and Resource specifications. - Documented key changes including the introduction of person tokens, changes to token claims, and updated revocation processes. - Specified required and optional metadata for both Person Server and Resource implementations. - Outlined new requirements for authorization and token verification processes.
…dentifiers - rename token_endpoint to auth_token_endpoint and parse person_token_endpoint - adopt session-token/person-token access modes and drop login_endpoint - add Signature Keys -09 revoked_jwt/clock_skew with a symmetric created window - type the draft-11 token, polling and revocation error vocabularies - accept uppercase agent-identifier local parts - retarget ApiSurface and docs inventory to the v11 plan folder 📚 - Generated by Copilot
Draft-11 auth tokens name no agent, so a protected-channel ticket now records the JWK thumbprint of the auth token's cnf.jwk, and redemption requires the subscribe request to be signed by the same key (Q5). 📚 - Generated by Copilot
Resources answer agent tokens with requirement=person-token; the PS issues
person tokens at person_token_endpoint; resource tokens name the presented
person or auth token (ps, sub, presented_jti, agent_jkt); token requests
carry resource_token + presented_token and servers verify the pair.
- Auth and resource tokens carry ps/sub/tenant/mission_s256; agent, act
and mission claims, act chains, MaxActDepth, MissionClaim, the
AAuth-Mission header and the aauth-mission component are removed.
- The AS accepts only jwks_uri PS callers (direct agent mode removed).
- Missions: approval envelope {s256, mission}, update and completion at
{mission_endpoint}/{s256}, mission_not_found / mission_terminated.
- Revoked source tokens on first requests return revoked_<param>_token,
or 401 Signature-Error revoked_jwt for the Signature-Key token.
- Consumer helpers: ChallengeHandler handles both legs,
RequestPersonTokenAsync, ExchangeAsync(ps, rt, presented),
GetAAuthVerifiedAssertion, R3Challenge.Challenge.
- Samples, Conformance, R3 and core tests migrated; samples echo ps/sub.
Snippet, docs and GuidedTour narrative drift remain for the Phase 10 sweep.
📚 - Generated by Copilot
📚 - Generated by Copilot
The v10 plan is a historical record; links to act-chain and mission-header sources and tests now point at the v0.10.0-alpha.1 tag where they exist. 📚 - Generated by Copilot
The SampleApp mission pages and the Documents walkthrough displayed the removed AAuth-Mission header, mission approver and agent-only exchange. They now request a person token (with mission_s256), present it, and exchange the resource token together with the presented token. The WithMission XML doc describes mission_s256 instead of the header. 📚 - Generated by Copilot
Draft-11 has no mission_aware resource metadata and no AAuth-Mission header; missions reach resources as mission_s256 in person and auth tokens. Remove the Bookings config, metadata member and root echo, and the SDK doc comments that cited the flag as an AdditionalMetadata example. 📚 - Generated by Copilot
Rewrite snippets and prose for person tokens and the presented-token pair: the person-token then auth-token challenge, ps/sub resource and auth token builders, VerifyResourceTokenAsync + VerifyPresentedTokenAsync, missions by mission_s256 with the approval envelope and mission-endpoint update and completion, call chaining without act chains, revocation error rules, and key-bound Events tickets. Configuration tables drop PersonServerAudience and MaxActDepth. The docs-context test asserts draft-11 wording. GuidedTour snippets and the docs inventory follow once the tour migrates. 📚 - Generated by Copilot
The resource verification middleware answered a revoked agent, person or auth token with Signature-Error invalid_jwt. Draft-11 #token-revocation (L2764) requires 401 with error=revoked_jwt; an inventory conflict on a live token stays invalid_jwt. 📚 - Generated by Copilot
Draft-11 missions have no approver field; the mission is held by the PS that approved it. StoredMission, AAuthGovernancePipelineOptions and the deferred-consent entries now name that PS PersonServer, matching Mission.PersonServer and MissionApprovalContext. IMissionApprover keeps its name: it is the PS component that decides a proposal. 📚 - Generated by Copilot
…line 📚 - Generated by Copilot
AAuthTokenHolder required the carrier token's account to match the request's account. A person token MUST NOT carry `account` (#person-tokens, L898), so any request naming an account fell back to the agent token and looped on person_token_required. The account binds at the resource token and the auth token, which keep the check. 📚 - Generated by Copilot
…oken issuers In four-party the AS issues auth tokens but the PS issues person tokens, so checking both against TrustedAuthTokenIssuers forced resources to trust the PS as an auth-token issuer. AAuthVerificationOptions, AAuthResourcePipelineOptions and AAuthServerOptions gain TrustedPersonServers / IsTrustedPersonServer; when unset, person tokens fall back to the auth-token issuer policy (three-party). 📚 - Generated by Copilot
Catalog and Wallet demo sessions request and present a person token; the Concierge echoes ps/sub/mission_s256 and chains downstream consent for /wallet; four-party resources trust the PS through TrustedPersonServers. SampleApp specs and shared helpers assert ps and a directed sub with no agent/act, and the sub-agent page compares the auth token cnf with the worker key instead of a hard-coded badge. The PS wallet-revoke route no longer passes the agent id as the scope limit. 📚 - Generated by Copilot
…ken leg Each PS-governed flow now shows the agent token's person-token requirement, the /person request, presenting the person token for a resource token that names it, and the exchange with presented_token. Mission flows request the person token with mission_s256; the sub-agent flow gains the worker person-token step; summaries show ps/sub/ mission_s256 instead of agent/act/approver. CodeSnippets, step plans, PLAN_STEPS and the tour specs follow, and the docs inventory is current. 📚 - Generated by Copilot
The handler no longer emits an AAuth-Mission header; it tags requests with the mission's mission_s256 so person tokens are requested under the mission. Remove the remaining header wording from AAuthClientBuilder, map AAuthTokenType in the ApiSurface grouping, and regenerate the API and docs surface maps. 📚 - Generated by Copilot
📚 - Generated by Copilot
Direct PS, AS and R3 token responses returned polling `408 expired` when a source token expired before issuance. That code is for pending polls (#polling-error-codes); a fresh request now answers 400 expired_<parameter>_token for a parameter token, 401 Signature-Error expired_jwt for the Signature-Key token, and mission_terminated when a mission's expires_at set the ceiling. At the AS and R3 the agent token is recorded as the agent_token parameter, so it reports expired_agent_token. 📚 - Generated by Copilot
Playwright-started servers now run with a scratch HOME (wiped per run, AAUTH_E2E_HOME to keep one) and real NuGet/dotnet caches, so a stale key under ~/.aauth no longer aborts MockAgentProvider. FileKeyStore names the offending key file, and the R3 sample creates its data folder instead of writing r3-audit.sqlite into the project when the folder is missing. 📚 - Generated by Copilot
…back mapping Belongs with 7a35bd0; the new file was untracked when that commit was made. 📚 - Generated by Copilot
…ations Document-release, jkt-jwt and verification-middleware now cite the v11 protocol and signature-key-09. The old §6.3 citations named a section that exists in neither -08 nor -09; egress admission is §7.3 and pseudonymity §8.1. The Catalog page states that draft-11 R3 removed the OpenAPI Gateway vocabulary it still uses, pending the Phase 8 redesign. 📚 - Generated by Copilot
…used Upstream Token Verification step 4 (L1835): after the agent provider revokes the calling agent's agent token, the PS rejects an intermediary's request carrying the upstream token issued from it with revoked_upstream_token. The PS token graph already records that ancestry, so this pins the existing behaviour in both three- and four-party flows. 📚 - Generated by Copilot
…p} contract
Revocation requests carry {jti, exp}; the recipient keys them by the
verified caller identity, so a caller revokes only its own tokens and a
body issuer is never trusted. Unseen tokens are recorded and answered
200, and the cascade reports each downstream recipient in a `downstream`
array (revocation_unsupported / revocation_unavailable) instead of 502.
AAuthRevocationOptions.IsAcceptedIssuer replaces the draft-10 trusted-PS
revoker model and answers unsupported_iss; RevocationClient returns a
parsed RevocationResult. The PS answers agent providers with an empty
body and ends federated access by revoking its person token at the AS,
which the Wallet demo now shows. Deferred 202 revocation and
rate_limited remain out of scope.
📚 - Generated by Copilot
When a proposal names resources and the PS endpoints share the app with the governance endpoints, the approval (direct or deferred poll) carries a mission-bound person token per resource the identity asserter asserts (#mission-approval). Each token binds the agent key, carries mission_s256, expires by the earliest of agent token, mission expiry and one hour, and is tracked as a grant of the agent token so revocation cascades. The member is present whenever the PS issued for named resources, even when it declined them all. IMissionPersonTokenIssuer is the seam; governance hosted without a PS omits person_tokens. 📚 - Generated by Copilot
… agents (Phase 10b) - Concierge registers one downstream agent (self-issued, ChainFromHttpContext, no interaction capability); the exchange capture is per inbound request. - MissionAgent and AgentConsole run a generic host: MissionAgent uses a registered enrolled agent and its keyed governance client; AgentConsole registers the jwt agent and creates the signing-mode demonstrations through IAAuthAgentFactory. - EventDemoSession creates its agent once through IAAuthAgentFactory. - Fix: AAuthSigningHandler gives each (key, method, authority, path) a unique created, so cached-token requests in one second no longer collide in a resource replay cache. 📚 - Generated by Copilot
… 10c) - IPersonPendingObserver: every registered observer (keyed by Person Server name, then unkeyed) sees each request the PS parks. MockPersonServer's ConsentRegistry observes instead of the bridge store registering entries. - BrowserInteraction.CompleteOutOfBandAsync runs a host-channel decision under the request's gate and consumes the code when it applies (#user-interaction); Consume() is internal. PersonConsentDecisions uses it. - A four-party request waiting only on the AS polls as a bare 202 without AAuth-Requirement; the guided tour keeps polling until the next requirement. - Docs: token-issuance covers both seams. Tests: PendingConsentSeamTests and WaitingOnAccessServer_PendingCarriesNoRequirement. 📚 - Generated by Copilot
- Grep evidence for builders, Build() calls and configuration reads. - make demo verified end to end; Keycloak profile green. - Teaching panes and dashboard URLs deferred to Phase 11 (logged). 📚 - Generated by Copilot
- ConfigurationReferenceTests: every public option property of the agent, resource, PS, AS, trust, discovery, challenge and interaction options must have a row in docs/reference/configuration.md; 44 gaps documented and duplicate tables folded. - configuration.md: extensibility ladder, seam x form table, trust in four forms, multi-tenant and KMS signer examples (all compiled). - GuidedTour FullAutomatic and CallChainConvenience snippets show the DI path. - Implementation log: deleted-symbol sweep table and ApiSurface removal review against Phase 0; Phase 11 DoD ticked. 📚 - Generated by Copilot
- Independent read-only review against P1-P6, R0, phase DoDs and the v11 spec rows for Phases 1, 5 and 6: no P0-P3 findings. Citations re-derived; own spot checks on egress, trust fail-closed and the exchange channel. - Ruled: scope step-up answering 403 is conformant (v11 L641 MAY) and a wire change is out of scope; async signature-key providers stay as ruled in P7. - Final gates: Playwright --retries=0 78 passed / 1 skipped, Keycloak federated-deferred passed. Phase 12 DoD ticked; plan complete. 📚 - Generated by Copilot
…y (Phase 1) - AddAAuthResource post-configures AAuthVerificationOptions.ResourceIdentifier from Issuer; the middleware never takes the expected audience from the token and rejects auth/person JWTs with invalid_request when no identifier is known (SDK-01, CRITICAL). - Demo admin roles match the exact agent id aauth:demo@ap.example in the mock PS and federated AS (SMP-01). - Docs: audience binding, known-non-conformance callouts, pessimistic README and SPEC-VERSION claims. - Plans: draft-11 compliance audit and remediation plan. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- R13: never future-date `created`; wait for the next free second on an exact replay-tuple collision (owner ruling Q1) with an aauth.signing.created_wait metric; body requests fail closed without Content-Type; Signature-Key label consistency; typed additional_signature_components seeds first-request signing (SDK-16, A02-HIGH-002, A01-M01, A04-04). - R16: shared metadata URL validation (https, no query/fragment) for producers and consumers; strict AgentId sub-agent structure; locked-down development loopback exception that fails in Production (owner ruling Q2); AP event_endpoint and localhost_callback_allowed (A04-01/02/03/05/06, A07-002). - R17: typed Events store outcomes (exhausted -> 404), optional subscription body, body components only when a body is present (A24-01/02/03, S06-01). - Samples without a launch profile now run as Development. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…thorization (Phase 3) - R14: reject JOSE crit; companion issuer-key resolution for app-specific jwt; zero exp skew; single scheme gate (ChallengeOptions.AllowedSignatureKeySchemes removed); central 401 Signature-Error writer; untrusted issuer -> invalid_key; SDK transport pinned to TLS 1.2/1.3 (SDK-17, A01-H01, A01-M02, A03-HIGH-001/002, A19-HIGH-001, A21-TLS-01). - R02: AAuthResourceOptions.AccessServer declares four-party and pins AS-issued aauth-access.json tokens; three-party pins aauth-person.json; PS pins AS responses (SDK-02, A17-002). - R03: authorization endpoint requires a person token (requirement=person-token) with an R3 extension seam; AgentTokenRequired accepts only agent tokens; 400 for non-JSON; Inbox drops /authorize (SDK-08, SDK-18, A07-001, A09-HIGH-003, A08-03, SMP-04, DOC-04). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- ChallengeHandler's deferred auth-token path uses the shared poll core: honours Retry-After (0 = immediate), backs off on 429 slow_down, and re-exchanges a fresh resource token on the same Location (SDK-11, A14-MED-004). - Closed-table polling/token error helpers own each registered status: invalid_code 410 (unknown/consumed pending ids), expired 408 then 410, held-invocation expiry fixed (SDK-12, SDK-13). - Invented codes removed from src (unknown_pending, unknown_interaction, request_withdrawn, untrusted_*, policy_error); untrusted signers answer 401 invalid_key (A19-HIGH-003/004, D07-05). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
… step-up (Phase 5, R06) - AAuthSourceGuard rechecks typed source dependencies immediately before federating or minting; a revoked person token is never presented to an AS and the pending request ends 403 revoked with a detail (SDK-05, A20-002). - A revoked auth token's 401 also carries requirement=person-token (A20-003). - RequireAAuth(scope:) steps a valid but narrower auth token up with 401 requirement=auth-token and a new resource token (Q8). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…n (Phase 5, R05) - The PS records provenance for every person/auth token it issues or federates, in the shared token inventory; upstream validation fails closed with invalid_upstream_token when no record exists and revoked_upstream_token when the calling agent or binding is revoked; quotas and exp+skew pruning (SDK-04). - Interaction chaining: intermediaries mint their own interaction code and Location and complete the original request (A18-003); Concierge and SampleApp updated (SMP-03); docs DOC-05, D07-02. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…tions (Phase 5 e2e)
- Concierge's own /chain-interaction/{id} page is reachable by the browser;
its pending URLs stay AAuth-protected.
- Wallet walkthroughs and specs expect 401 requirement=auth-token step-up for
a narrower grant instead of 403 (Q8); tour call-chain drives the
intermediary-owned interaction URL.
- Gates: unit suites green; Playwright 78 passed, 1 skipped; Keycloak
federated-deferred passed.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…s revoked (Phase 5) AAuthSourceGuard monitors source dependencies while the guarded action runs and cancels the linked token on revocation; the pending request ends 403 revoked. Negative control: DeferredFederationTests RevokedPresentedTokenCancelsInFlightFederationSend (Q7). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…itlement (Phase 6) - R3Enforcement returns a SingleUse handle keyed by (auth iss, jti), shared with the 202 held path; a missing gate, jti or exp answers single_use_required (SDK-03, DOC-06). - Issuance audit records ps, sub and agent_jkt; SqliteR3AuditSink schema updated (SDK-19). - Expiring, URI-bound document entitlements for both AS and PS readers (A23-003); authoritative operation validation before minting and duplicate bare-id rejection (A23-004, A22-MED-001); R3 docs shape (D07-04). - Sample R3 AS registers the Catalog's merged operations. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ps check (Phase 7, R10) - IdentityAssertion carries a never-emitted AAuthPersonKey; an atomic IAgentPersonBindingStore binds (PS, agent iss, agent sub) to one person and denies a different person until the generationed binding is revoked (SDK-07). - Default directed sub = HMAC(person key, resource) over a key ring, persisted with its key version; first issuance for a resource records enrollment and fetches resource metadata (A11-03, A11-04). - Missing enrollment fails closed (invalid_presented_token / invalid_upstream_token); no inference shims. - PS governance endpoints reject agent tokens whose ps is absent or foreign (A15-002); sample admin requires the exact (issuer, agent id) (SMP-01). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…tion reasons (Phase 7, R09) - One MissionStatusEvaluator on every PS decision path, including pending and federated; a mission past expires_at terminates with reason expired, which wins over generic deferred expiry (SDK-14). - IMissionStore keyed by (PersonServer, s256); TerminateAsync(reason) keeps the first reason and never revives (A16-001, A16-003). - Absent, foreign-agent and foreign-PS missions answer an identical mission_not_found (A16-004). - Docs D04-002, D05-02, D08-05. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ication limits (Phase 7, R08) - updated_request recomputes bounds and source dependencies from the replacement pair under the pending lifecycle gate (SDK-06). - One validator for platform (registry), device (printable Unicode, <=64) and capabilities, shared by the agent and the PS; capability and platform constants move to AAuthConstants (A12-02, A12-03, A13-05). - Clarification rounds are counted in one place, including federated triage (A12-04); the agent enforces the clarification timeout and pre-validates a replacement pair (A13-02, A13-03). - Log: spec author opened dickhardt/AAuth#222 (optional nonce); Q1 unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…strict objects (Phase 8, R12) - .WithGovernance() declares the governance paths once and MapAAuthPersonServer() maps them; interaction_endpoint is omitted unless governance is on; MapAAuthGovernance fails fast on conflicting paths (SDK-10, DOC-07). - Relay results are Answered, Pending (202 + Location) or Unavailable (424); the default relay is Unavailable (SDK-09). - Non-object parameters/result answer 400; audit entries keep both (A15-004, A15-005); docs D05-01, D05-03. - Fix a flaky metric test (process-wide meter). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ub rule (Phase 9, R07) - Collapse is declared once (resource issuer, linked AS role, expected AS issuer); it runs the AS policy internally and mints dwk=aauth-access.json; a missing or mismatched linked AS fails closed (A17-001, D06-02). - 402 responses settle through a narrow IAAuthPaymentSettler (no JWTs) with a billing-relationship cache, then poll the same Location through 202 steps; with no settler the request ends 403 denied (A17-003, A19-HIGH-005). - An AS never requests sub in requirement=claims and the PS never sends it (S04-01). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…st relay (Phase 10, R15) - Automatic two-key refresh removed; RefreshTwoKeyAsync documents rebuilding with the returned key and token together (SDK-15). - Resource-token login_hint reaches the PS unchanged (A08-02). - Returned auth tokens are signature-verified by default with pinned dwk; sub-agent tokens verify against the worker key (A10-01). - Cached person/auth tokens inside the five-minute margin are re-acquired; producers cap agent tokens at 24h (A06-02, A05-02). - Resource interactions are relayed to the PS first, falling back on 424 or when the PS does not report interacting (A13-04, A07-004). - Strict AAuth-Access handling; mission capabilities unioned into a strict SF List AAuth-Capabilities header (A07-003, A07-005, A07-007). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…on store (Phase 11a) - Owner's consent-dashboard edits: /admin/reset keeps decided history (ConsentRegistry.DropPending); mission creation entries carry their s256 once approved. - The hand-written /mission-interaction handler is gone; .WithGovernance() + MapAAuthPersonServer() map it, and the sample relay answers questions or returns Unavailable (SMP-02). - Sample pending errors use 410 invalid_code; revocation demo returns 200 with downstream outcomes (S01-04); README documents mission completion and the token pair (S01-02, S01-03). - Legacy IMissionStore.GetAsync(s256) and SetStateAsync removed; completion records the completed reason. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ric-scheme lessons, redaction (Phase 11b) - GuidedTour and Concierge poll through the SDK DeferredPoller and validate same-origin pending Locations (S08-01/02/03, S09-01, S05-002). - AAuth identity defaults to jwt; hwk/jwks_uri/jwks lessons are labelled as generic Signature-Key demos (S07-01, Q31); tour requests send AAuth-Capabilities (S09-02). - Resources accepting person tokens publish revocation endpoints that accept every issuer they trust (S03-02, S03-03). - Token-bearing output is redacted by default; the tour parses protocol state from raw captures (Q32, S10-001); LOW prose fixes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ored claims (Phase 12, R19) - getting-started teaches the draft-11 flow: person token, resource token with presented_jti, PS request with resource_token + presented_token (DOC-01, D01-04). - Signing-mode docs: jwt for AAuth agents; hwk/jwks_uri/jwks are generic Signature-Key; jkt-jwt only for AP key refresh (DOC-02, D02-02, Q31). - Five access modes and current terminology across docs and READMEs. - README and SPEC-VERSION claims restored with test-class citations; the deliberate deviations (Q1 throughput + AAuth#222, Q2 loopback, Q19, in-flight revocation polling) are listed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…red errors, binding revocation order - AAuthSourceGuard fails closed when a registered source is missing from the inventory (RA-CHAIN-001); AS token endpoint emits server_error instead of policy_unavailable (RA-HIGH-001). - Agent-person binding revokes the inventory generation before the binding store (SDK-07 review P1). - Remove the last C1 shims (old ChallengeHandler ctor, TourSession.CanSwitchMode). - LOWs: https r3_uri, base64url SHA-256 digests, strict ISO 8601 mission timestamps, AuthTokenBuilder dwk/ps consistency, equal-work mission lookup. - Re-audit reports, review outcomes, corrected claim citations, superseded deviation entries; plan DoD complete. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The Guided Tour now records the user-decision step and starts polling as soon as an interaction is surfaced, whoever hosts the consent page (PS dashboard, Access Server, Inbox, document owner or Concierge relay). "Run all" waits on the poll instead of stopping at a consent link. - Consent links live in one polling banner (also for in-step waits) and only open a tab; this removes the Federated "only valid at step 9" error and the Run all re-enable race. - Reset cancels in-step consent waits. - A capability poll that answers with a new interaction (Document Release, Wallet Protocol) chains straight into the next wait. - Call Chain hop 2 (Concierge relay) offers the PS dashboard, uncoded because the relay code is the Concierge's; same in the SampleApp. - Poll budget is five minutes; e2e specs, helpers, README and the docs inventory are updated. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Align README, docs/**, sample READMEs and SPEC-VERSION with draft-11 facts and compliance rulings; fix rendered code/text in GuidedTour, SampleApp, CapabilitySupport and EventSupport (all displayed snippets scratch-compile). Refresh docs and API surface inventories; log the pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AAuth draft-11 migration and compliance remediation
Migrates the .NET AAuth SDK, samples and docs from draft-10 to
draft-ietf-aauth-protocol-11, then hardens them against a full
draft-11 compliance audit.
What's included
AAuth,AAuth.R3andAAuth.Events.audbinding, registered-only error codes,{jti, exp}revocation, egress admission policy, signaturecreatedreplay handling, four-party AccessServer metadata..agent/decks/aauth-community-collaboration.html.Deliberate deviations
Listed in SPEC-VERSION.md:
created(one identical request per second per key/method/authority/path); an optional nonce is being discussed upstream in Replay tuple limits an agent to one request per second per (key, method, authority, path) dickhardt/AAuth#222.Validation