[Openid-specs-risc] Subject identifiers / categories call

Atul Tulshibagwale atultulshi at google.com
Wed Aug 26 01:09:34 UTC 2020


Hi all,
We had the call earlier today to discuss multiple subject identifiers and
subject categories in subject identifiers. Annabelle wasn't able to attend.
The following is a (incomplete) summary of the discussion:

   1. We agreed that the subject processing can be greatly simplified if
   when we specify multiple subjects in a single event, we always interpret
   that to mean that the intended subject of the event is an "AND" of all
   subject identifiers.
   2. An interesting proposal from Praveen (Microsoft) was that we could
   have a different subject-type that had fields like "user" and "device".
   Upon discussion we figured out each one of these fields would require the
   same subject-identifier structure, so it won't be any different from the
   multiple subject-identifiers proposal being considered right now. It'll be
   great if Praveen can share his example to this list anyway, for further
   discussion.
   3. We agreed that defining event-specific subject identifier
   combinations would not be good for implementers.
   4. subject-categories are required to disambiguate use-cases where a
   subject identified by a subject-type of say, phone-number or iss-sub need
   to be classified as either a device or a user.

I've added the notes to the weekly sync doc
<https://docs.google.com/document/d/1ZFwJJDwwSBNKX35VObClC1ctMbMMuHJtr5qY-7xsLW8/edit?usp=sharing>,
but since I was actively participating in the discussion, the notes are
(very) incomplete.

Atul
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20200825/752a98d0/attachment.html>


More information about the Openid-specs-risc mailing list