Skip to content

Conversation

c2bo
Copy link
Member

@c2bo c2bo commented Sep 30, 2024

Adds support for historical resolution of status as an optional feature.

Closes #138
Rendered Version: https://drafts.oauth.net/draft-ietf-oauth-status-list/c2bo/historical-resolution/draft-ietf-oauth-status-list.html

I will take another look at the wording / normative text and mark as ready for review when I am done.

@c2bo
Copy link
Member Author

c2bo commented Oct 9, 2024

todo:

  • fix the references to this in privacy considerations
  • fix some wording / language

Copy link

@decentralgabe decentralgabe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the language looks good, thanks for including it.

I will only add that while there may be privacy risks, there are legitimate business cases that require such historical data, such as guaranteeing compliance with financial regulation. In these cases, user privacy is made better by using this specification (as opposed to amore privacy-eroding solution), even if maximal privacy is not achieved. I hope the privacy section can speak to this nuance.

@paulbastian paulbastian added this to the -05 milestone Oct 16, 2024
@c2bo c2bo marked this pull request as ready for review October 16, 2024 10:55
@c2bo c2bo requested a review from tplooker as a code owner October 16, 2024 10:55
@c2bo c2bo requested a review from paulbastian October 16, 2024 11:00
Co-authored-by: Tobias Looker <[email protected]>
Copy link
Contributor

@paulbastian paulbastian left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The whole text is in the Security Considerations section. I believe we should move the normative text to the section 8.

@c2bo
Copy link
Member Author

c2bo commented Oct 21, 2024

The whole text is in the Security Considerations section. I believe we should move the normative text to the section 8.

Good point - I moved the whole part to the end of Section 8.

@paulbastian paulbastian merged commit 1ae1692 into main Oct 21, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Support an optional feature for historical resolution
4 participants