Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Claim 'vct' is missing in Type Metadata Format #241

Open
jtalir opened this issue Jul 12, 2024 · 4 comments
Open

Claim 'vct' is missing in Type Metadata Format #241

jtalir opened this issue Jul 12, 2024 · 4 comments
Assignees

Comments

@jtalir
Copy link

jtalir commented Jul 12, 2024

I'm not sure why 'vct' is not (as REQUIRED) in 6.2 Type Metadata Format. Is it bug or is this some sort of implicit? It is in the 6.1. Type Metadata Example and also it is twice referenced in 6.3.5 From Type Metadata Glue Documents: "the Consumer MUST ensure that the vct claim in the credential matches the one in the Type Metadata document" and "the Consumer MUST ensure that the value of the extends property in the Type Metadata document matches that of the vct in the Type Metadata document"

@bc-pi
Copy link
Collaborator

bc-pi commented Jul 30, 2024

This does seem like an oversight but I'll defer to @danielfett to ask if there was a reason behind the omission or if vct needs to be added to that section https://www.ietf.org/archive/id/draft-ietf-oauth-sd-jwt-vc-04.html#name-type-metadata-format

@babisRoutis
Copy link
Contributor

I believe that vct & vct#integrity have to been added to the section mentioned by @bc-pi ,

Currently, examples do include those two, and to me are not aligned with the section.

@jtalir
Copy link
Author

jtalir commented Dec 2, 2024

I believe that vct & vct#integrity have to been added to the section mentioned by @bc-pi ,

Currently, examples do include those two, and to me are not aligned with the section.

I don't think so. Claim vct#integrity belongs into sd-jwt vc, not into type metadata. In the example section #type-metadata-example, there is first example with sd-jwt vc and only second example is with type metadata. In type metadata vct serves as "backward reference" and not as a link to be resolved.

@babisRoutis
Copy link
Contributor

Dear @jtalir

On second thought, I agree with this.
Mainly I was missing vct from Type metadata.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants