[Openid-specs-risc] subscription/enrolment - why do we need a receiver API for it?

Hardt, Dick dick at amazon.com
Sat Feb 18 20:04:07 UTC 2017

Good question

When Adam was labeling the implicit and explicit RPs, I originally thought the implicit was the OAuth flow as there was an implicit subscription by the RP of RISC events.

-- Dick

On Feb 18, 2017, at 8:55 AM, Phil Hunt <phil.hunt at oracle.com<mailto:phil.hunt at oracle.com>> wrote:

A few questions following Thursday's F2F...

Is there ever a time in RISC where a user who has chosen to federate would not be added to the stream between providers?  And if so, doesn't the IDP already know this? Why wouldn't an IDP who is a transmitter just do this automatically?

Why wouldn't an IDP just put a subject, who has consented to federation, in the event list for an audience automatically?

What purpose does it serve to have the receiver call back to register the subject if the receiver has already agreed to an event stream?


Oracle Corporation, Identity Cloud Services & Identity Standards
phil.hunt at oracle.com<mailto:phil.hunt at oracle.com>

Openid-specs-risc mailing list
Openid-specs-risc at lists.openid.net<mailto:Openid-specs-risc at lists.openid.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20170218/c3346d7b/attachment.html>

More information about the Openid-specs-risc mailing list