George Fletcher

Results 5 issues of George Fletcher

Instead of using `MUST NOT`, I'd make it a positive statement. REQUIRED. An `authorization_details` response claim MUST only be returned if an `authorization_details` parameter is present in the request. ...

The non-normative example in section 6.1 uses HTTP Basic authentication for client authentication. I'd recommend using a stronger client authentication mechanism in the example.

The text in section 5.3 uses `invalid_scope` while the non-normative example has an error value of `invalid_request`. I would recommend making them consistent.

Creating this issue here from the [bitbucket issue](https://bitbucket.org/openid/connect/issues/2053/signatures-in-jwt-examples-are-not-all) . For those examples where the signature should validate we need to publish a public key so that developers can validate the...

clarification

Should the specification be more explicit about what consent the wallet should collect from the user. During the working group meeting prior to IIW, two wallet consents were discussed. 1....