Skip to content

Incorporate Aaron Parecki's review suggestions - #27

Merged
selfissued merged 7 commits into
mainfrom
mbj-aaron
Nov 7, 2025
Merged

Incorporate Aaron Parecki's review suggestions#27
selfissued merged 7 commits into
mainfrom
mbj-aaron

Conversation

@selfissued

Copy link
Copy Markdown
Collaborator

Fixes #17

Comment thread draft-ietf-oauth-rfc8725bis.md Outdated
Comment thread draft-ietf-oauth-rfc8725bis.md Outdated
Comment thread draft-ietf-oauth-rfc8725bis.md Outdated
Comment thread draft-ietf-oauth-rfc8725bis.md Outdated
selfissued and others added 4 commits November 7, 2025 11:27
Co-authored-by: Yaron Sheffer <yaronf.ietf@gmail.com>
Co-authored-by: Yaron Sheffer <yaronf.ietf@gmail.com>
Co-authored-by: Yaron Sheffer <yaronf.ietf@gmail.com>
Co-authored-by: Yaron Sheffer <yaronf.ietf@gmail.com>
@aaronpk

aaronpk commented Nov 7, 2025

Copy link
Copy Markdown
Member

Thanks. I reviewed the changes and I don't see these two of my earlier comments addressed in this:

  • There is still a mention of the "none" algorithm being acceptable over TLS
  • The "Explicit Typing" section still starts with the vague "Sometimes, one kind of JWT can be confused for another"

@selfissued

Copy link
Copy Markdown
Collaborator Author

Thanks, Aaron.

There is still a mention of the "none" algorithm being acceptable over TLS

I'll look at the "none" text and update the PR. Sorry I missed that one!

The "Explicit Typing" section still starts with the vague "Sometimes, one kind of JWT can be confused for another"

The new paragraph after this one, giving an example of possible confusion, was intended to do what you asked in your review, which was:

This is kind of vague and would benefit from more explicit examples.

So I'd either ask that you check off the last request as completed or provide more input as to particular additional text changes you'd like.

Thanks again!

@selfissued

Copy link
Copy Markdown
Collaborator Author

@aaronpk, I deleted the text saying that the use of "alg":"none" can be acceptable when transmitting JWTs over TLS. Please re-review.

Comment thread draft-ietf-oauth-rfc8725bis.md Outdated
@aaronpk aaronpk mentioned this pull request Nov 7, 2025
9 tasks
@selfissued
selfissued merged commit 2ab07d7 into main Nov 7, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Review by Aaron Parecki

3 participants