Skip to content

Commit 158334c

Browse files
author
ID Bot
committed
Script updating gh-pages from 8d38c05. [ci skip]
1 parent 9fba0d9 commit 158334c

File tree

2 files changed

+54
-54
lines changed

2 files changed

+54
-54
lines changed

pb/ad_review/draft-ietf-oauth-status-list.html

Lines changed: 25 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -1978,9 +1978,9 @@ <h3 id="name-status-list-token-in-cwt-fo">
19781978
d2845820a2012610781a6170706c69636174696f6e2f7374617475736c6973742b63
19791979
7774a1044231325850a502782168747470733a2f2f6578616d706c652e636f6d2f73
19801980
74617475736c697374732f31061a648c5bea041a8898dfea19fffe19a8c019fffda2
1981-
646269747301636c73744a78dadbb918000217015d58402574c628fb3ca309b51b47
1982-
0d6fca529108d1adf5bc8fb6eb112f58aad3d0d4cf8cfb830a8f88756a1035bd5259
1983-
e7febfd481970538f1a064e0264fd8fa319dbe
1981+
646269747301636c73744a78dadbb918000217015d58408681dd0578a1e156e9444c
1982+
ad40c00b8aa0ef364a3620cc5f9c9739f1cbd366049f274eea385d84566a5c658c9c
1983+
1e71539d148b7c13c8a5f44da5961ba0bd4f42
19841984
</pre><a href="#section-5.2-9" class="pilcrow"></a>
19851985
</div>
19861986
<p id="section-5.2-10">The following is the CBOR Annotated Hex output of the example above:<a href="#section-5.2-10" class="pilcrow"></a></p>
@@ -2005,12 +2005,12 @@ <h3 id="name-status-list-token-in-cwt-fo">
20052005
6269747301636c73744a78da # "bits\x01clstJxÚ"
20062006
dbb918000217015d # "Û¹\x18\x00\x02\x17\x01]"
20072007
58 40 # bytes(64)
2008-
2574c628fb3ca309b51b470d # "%tÆ(û&lt;£\x09µ\x1bG\x0d"
2009-
6fca529108d1adf5bc8fb6eb # "oÊR\x91\x08Ñ\xadõ¼\x8f¶ë"
2010-
112f58aad3d0d4cf8cfb830a # "\x11/XªÓÐÔÏ\x8cû\x83\x0a"
2011-
8f88756a1035bd5259e7febf # "\x8f\x88uj\x105½RYçþ¿"
2012-
d481970538f1a064e0264fd8 # "Ô\x81\x97\x058ñ\xa0dà&amp;OØ"
2013-
fa319dbe # "ú1\x9d¾"
2008+
8681dd0578a1e156e9444cad # "\x86\x81Ý\x05x¡áVéDL\xad"
2009+
40c00b8aa0ef364a3620cc5f # "@À\x0b\x8a\xa0ï6J6 Ì_"
2010+
9c9739f1cbd366049f274eea # "\x9c\x979ñËÓf\x04\x9f'Nê"
2011+
385d84566a5c658c9c1e7153 # "8]\x84Vj\e\x8c\x9c\x1eqS"
2012+
9d148b7c13c8a5f44da5961b # "\x9d\x14\x8b|\x13È¥ôM¥\x96\x1b"
2013+
a0bd4f42 # "\xa0½OB"
20142014
</pre><a href="#section-5.2-11" class="pilcrow"></a>
20152015
</div>
20162016
</section>
@@ -2151,9 +2151,9 @@ <h3 id="name-referenced-token-in-cose">
21512151
d28443a10126a1044231325866a502653132333435017368747470733a2f2f657861
21522152
6d706c652e636f6d061a648c5bea041a8898dfea19ffffa16b7374617475735f6c69
21532153
7374a2636964780063757269782168747470733a2f2f6578616d706c652e636f6d2f
2154-
7374617475736c697374732f315840f1abf4b19c32ad64be61747ef6178eee743f69
2155-
0c7cf92b1e30d2476d85933b3c2ad50961540213fe48a1545a1f23f555859d5322c7
2156-
bc7706e6e1212dba0b882f
2154+
7374617475736c697374732f3158407aa5d4cea352652a4389546c65673f7991d405
2155+
df8e8d9949ca7e95e105b4816fe97d012f0b4ccc2010205cab9fc3d386cce24ab022
2156+
1436760cc9514a82e90c91
21572157
</pre><a href="#section-6.3-6" class="pilcrow"></a>
21582158
</div>
21592159
<p id="section-6.3-7">The following is the CBOR Annotated Hex output of the example above:<a href="#section-6.3-7" class="pilcrow"></a></p>
@@ -2178,12 +2178,12 @@ <h3 id="name-referenced-token-in-cose">
21782178
2e636f6d2f7374617475736c # ".com/statusl"
21792179
697374732f31 # "ists/1"
21802180
58 40 # bytes(64)
2181-
f1abf4b19c32ad64be61747e # "ñ«ô±\x9c2\xadd¾at~"
2182-
f6178eee743f690c7cf92b1e # "ö\x17\x8eît?i\x0c|ù+\x1e"
2183-
30d2476d85933b3c2ad50961 # "0ÒGm\x85\x93;&lt;*Õ\x09a"
2184-
540213fe48a1545a1f23f555 # "T\x02\x13þH¡TZ\x1f#õU"
2185-
859d5322c7bc7706e6e1212d # "\x85\x9dS"Ǽw\x06æá!-"
2186-
ba0b882f # "º\x0b\x88/"
2181+
7aa5d4cea352652a4389546c # "z¥ÔΣRe*C\x89Tl"
2182+
65673f7991d405df8e8d9949 # "eg?y\x91Ô\x05ß\x8e\x8d\x99I"
2183+
ca7e95e105b4816fe97d012f # "Ê~\x95á\x05´\x81oé}\x01/"
2184+
0b4ccc2010205cab9fc3d386 # "\x0bLÌ \x10 \«\x9fÃÓ\x86"
2185+
cce24ab0221436760cc9514a # "ÌâJ°"\x146v\x0cÉQJ"
2186+
82e90c91 # "\x82é\x0c\x91"
21872187
</pre><a href="#section-6.3-8" class="pilcrow"></a>
21882188
</div>
21892189
<p id="section-6.3-9">ISO mdoc <span>[<a href="#ISO.mdoc" class="cite xref">ISO.mdoc</a>]</span> may utilize the Status List mechanism by introducing the <code>status</code> parameter in the Mobile Security Object (MSO) as specified in Section 9.1.2. The <code>status</code> parameter uses the same encoding as a CWT as defined in <a href="#referenced-token-cose" class="auto internal xref">Section 6.3</a>.<a href="#section-6.3-9" class="pilcrow"></a></p>
@@ -2379,7 +2379,7 @@ <h3 id="name-status-list-request">
23792379
</ul>
23802380
<p id="section-8.1-5">If the Relying Party does not send an Accept Header, the response type is assumed to be known implicitly or out-of-band.<a href="#section-8.1-5" class="pilcrow"></a></p>
23812381
<p id="section-8.1-6">A successful response that contains a Status List Token <span class="bcp14">MUST</span> use an HTTP status code in the 2xx range.<a href="#section-8.1-6" class="pilcrow"></a></p>
2382-
<p id="section-8.1-7">A response <span class="bcp14">MAY</span> also choose to redirect the client to another URI using an HTTP status code in the 3xx range, which clients <span class="bcp14">SHOULD</span> follow. A client <span class="bcp14">SHOULD</span> detect and intervene in cyclical redirections (i.e., "infinite" redirection loops). See <a href="#redirects" class="auto internal xref">Section 11.4</a> for further guidance on redirects.<a href="#section-8.1-7" class="pilcrow"></a></p>
2382+
<p id="section-8.1-7">A response <span class="bcp14">MAY</span> also choose to redirect the client to another URI using an HTTP status code in the 3xx range, which clients <span class="bcp14">SHOULD</span> follow. See <a href="#redirects" class="auto internal xref">Section 11.4</a> for security considerations on redirects.<a href="#section-8.1-7" class="pilcrow"></a></p>
23832383
<p id="section-8.1-8">The following are non-normative examples of a request and response for a Status List Token with type <code>application/statuslist+jwt</code>:<a href="#section-8.1-8" class="pilcrow"></a></p>
23842384
<div class="alignLeft art-ascii-art art-text artwork" id="section-8.1-9">
23852385
<pre>
@@ -2397,8 +2397,8 @@ <h3 id="name-status-list-request">
23972397
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
23982398
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
23992399
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2400-
nR0bCI6NDMyMDB9.8ZzvWsUWWvdRDW2quZcLlj28y8Je3ejw20EqLk662ssZb9rwlnuA
2401-
gjjtBYBIIkv0VMUxaqQ_OL3CTmJZaDMkiw
2400+
nR0bCI6NDMyMDB9.y_p6jeXfKQyeXc0kYSSTT6guxCX88eqZscMmiHDRphWOZxA9XCtY
2401+
gqUjP-uw8LVaWZiymuRpbEwF_C0t5rxaDA
24022402
</pre><a href="#section-8.1-10" class="pilcrow"></a>
24032403
</div>
24042404
</section>
@@ -2505,8 +2505,8 @@ <h3 id="name-historical-resolution">
25052505
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
25062506
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
25072507
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2508-
nR0bCI6NDMyMDB9.8ZzvWsUWWvdRDW2quZcLlj28y8Je3ejw20EqLk662ssZb9rwlnuA
2509-
gjjtBYBIIkv0VMUxaqQ_OL3CTmJZaDMkiw
2508+
nR0bCI6NDMyMDB9.y_p6jeXfKQyeXc0kYSSTT6guxCX88eqZscMmiHDRphWOZxA9XCtY
2509+
gqUjP-uw8LVaWZiymuRpbEwF_C0t5rxaDA
25102510
</pre><a href="#section-8.4-7" class="pilcrow"></a>
25112511
</div>
25122512
</section>
@@ -2704,15 +2704,15 @@ <h3 id="name-key-resolution-and-trust-ma">
27042704
<h3 id="name-redirection-3xx">
27052705
<a href="#section-11.4" class="section-number selfRef">11.4. </a><a href="#name-redirection-3xx" class="section-name selfRef">Redirection 3xx</a>
27062706
</h3>
2707-
<p id="section-11.4-1">Clients that follow 3xx (Redirection) class of status codes should be aware of possible dangers of redirects, such as infinite redirection loops since they could be used as an attack vector for possible denial of service attacks on clients. The general guidance for redirects given in Section 15.4 of <span>[<a href="#RFC9110" class="cite xref">RFC9110</a>]</span> should be applied.<a href="#section-11.4-1" class="pilcrow"></a></p>
2707+
<p id="section-11.4-1">Clients that follow 3xx (Redirection) class of status codes should be aware of possible dangers of redirects, such as infinite redirection loops since they could be used as an attack vector for possible denial of service attacks on clients. A client <span class="bcp14">SHOULD</span> detect and intervene in cyclical redirections (i.e., "infinite" redirection loops). More guidance for redirects given in Section 15.4 of <span>[<a href="#RFC9110" class="cite xref">RFC9110</a>]</span> should be applied.<a href="#section-11.4-1" class="pilcrow"></a></p>
27082708
</section>
27092709
</div>
27102710
<div id="security-ttl">
27112711
<section id="section-11.5">
27122712
<h3 id="name-exiration-and-caching">
27132713
<a href="#section-11.5" class="section-number selfRef">11.5. </a><a href="#name-exiration-and-caching" class="section-name selfRef">Exiration and Caching</a>
27142714
</h3>
2715-
<p id="section-11.5-1">Expiration and Caching information is conveyed via the <code>exp</code> and <code>ttl</code> claims as explained in <a href="#expiry-and-caching" class="auto internal xref">Section 13.7</a>. Clients should check that both values are within reasonable ranges before requesting new Status List Tokens based on these values to prevent accidentally creating unreasonable amounts of requests for a specific URL. Status Provider could accidentally or maliciously use this mechanism to effectively DDoS the provided Status List Token URI.<a href="#section-11.5-1" class="pilcrow"></a></p>
2715+
<p id="section-11.5-1">Expiration and Caching information is conveyed via the <code>exp</code> and <code>ttl</code> claims as explained in <a href="#expiry-and-caching" class="auto internal xref">Section 13.7</a>. Clients should check that both values are within reasonable ranges before requesting new Status List Tokens based on these values to prevent accidentally creating unreasonable amounts of requests for a specific URL. Status Issuers could accidentally or maliciously use this mechanism to effectively DDoS the contained URL of the Status Provider.<a href="#section-11.5-1" class="pilcrow"></a></p>
27162716
<p id="section-11.5-2">Concrete values for both claims heavily depend on the use-case requirements and clients should be configured with lower/upper bounds for these values that fit their respective use-cases.<a href="#section-11.5-2" class="pilcrow"></a></p>
27172717
</section>
27182718
</div>

pb/ad_review/draft-ietf-oauth-status-list.txt

Lines changed: 29 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -727,9 +727,9 @@ Table of Contents
727727
d2845820a2012610781a6170706c69636174696f6e2f7374617475736c6973742b63
728728
7774a1044231325850a502782168747470733a2f2f6578616d706c652e636f6d2f73
729729
74617475736c697374732f31061a648c5bea041a8898dfea19fffe19a8c019fffda2
730-
646269747301636c73744a78dadbb918000217015d58402574c628fb3ca309b51b47
731-
0d6fca529108d1adf5bc8fb6eb112f58aad3d0d4cf8cfb830a8f88756a1035bd5259
732-
e7febfd481970538f1a064e0264fd8fa319dbe
730+
646269747301636c73744a78dadbb918000217015d58408681dd0578a1e156e9444c
731+
ad40c00b8aa0ef364a3620cc5f9c9739f1cbd366049f274eea385d84566a5c658c9c
732+
1e71539d148b7c13c8a5f44da5961ba0bd4f42
733733

734734
The following is the CBOR Annotated Hex output of the example above:
735735

@@ -752,12 +752,12 @@ d2 # tag(18)
752752
6269747301636c73744a78da # "bits\x01clstJxÚ"
753753
dbb918000217015d # "Û¹\x18\x00\x02\x17\x01]"
754754
58 40 # bytes(64)
755-
2574c628fb3ca309b51b470d # "%tÆ(û<£\x09µ\x1bG\x0d"
756-
6fca529108d1adf5bc8fb6eb # "oÊR\x91\x08Ñ\xadõ¼\x8f¶ë"
757-
112f58aad3d0d4cf8cfb830a # "\x11/XªÓÐÔÏ\x8cû\x83\x0a"
758-
8f88756a1035bd5259e7febf # "\x8f\x88uj\x105½RYçþ¿"
759-
d481970538f1a064e0264fd8 # "Ô\x81\x97\x058ñ\xa0dà&OØ"
760-
fa319dbe # "ú1\x9d¾"
755+
8681dd0578a1e156e9444cad # "\x86\x81Ý\x05x¡áVéDL\xad"
756+
40c00b8aa0ef364a3620cc5f # "@À\x0b\x8a\xa0ï6J6 Ì_"
757+
9c9739f1cbd366049f274eea # "\x9c\x979ñËÓf\x04\x9f'Nê"
758+
385d84566a5c658c9c1e7153 # "8]\x84Vj\e\x8c\x9c\x1eqS"
759+
9d148b7c13c8a5f44da5961b # "\x9d\x14\x8b|\x13È¥ôM¥\x96\x1b"
760+
a0bd4f42 # "\xa0½OB"
761761

762762
6. Referenced Token
763763

@@ -900,9 +900,9 @@ d2 # tag(18)
900900
d28443a10126a1044231325866a502653132333435017368747470733a2f2f657861
901901
6d706c652e636f6d061a648c5bea041a8898dfea19ffffa16b7374617475735f6c69
902902
7374a2636964780063757269782168747470733a2f2f6578616d706c652e636f6d2f
903-
7374617475736c697374732f315840f1abf4b19c32ad64be61747ef6178eee743f69
904-
0c7cf92b1e30d2476d85933b3c2ad50961540213fe48a1545a1f23f555859d5322c7
905-
bc7706e6e1212dba0b882f
903+
7374617475736c697374732f3158407aa5d4cea352652a4389546c65673f7991d405
904+
df8e8d9949ca7e95e105b4816fe97d012f0b4ccc2010205cab9fc3d386cce24ab022
905+
1436760cc9514a82e90c91
906906

907907
The following is the CBOR Annotated Hex output of the example above:
908908

@@ -925,12 +925,12 @@ d2 # tag(18)
925925
2e636f6d2f7374617475736c # ".com/statusl"
926926
697374732f31 # "ists/1"
927927
58 40 # bytes(64)
928-
f1abf4b19c32ad64be61747e # "ñ«ô±\x9c2\xadd¾at~"
929-
f6178eee743f690c7cf92b1e # "ö\x17\x8eît?i\x0c|ù+\x1e"
930-
30d2476d85933b3c2ad50961 # "0ÒGm\x85\x93;<*Õ\x09a"
931-
540213fe48a1545a1f23f555 # "T\x02\x13þH¡TZ\x1f#õU"
932-
859d5322c7bc7706e6e1212d # "\x85\x9dS"Ǽw\x06æá!-"
933-
ba0b882f # "º\x0b\x88/"
928+
7aa5d4cea352652a4389546c # "z¥ÔΣRe*C\x89Tl"
929+
65673f7991d405df8e8d9949 # "eg?y\x91Ô\x05ß\x8e\x8d\x99I"
930+
ca7e95e105b4816fe97d012f # "Ê~\x95á\x05´\x81oé}\x01/"
931+
0b4ccc2010205cab9fc3d386 # "\x0bLÌ \x10 \«\x9fÃÓ\x86"
932+
cce24ab0221436760cc9514a # "ÌâJ°"\x146v\x0cÉQJ"
933+
82e90c91 # "\x82é\x0c\x91"
934934

935935
ISO mdoc [ISO.mdoc] may utilize the Status List mechanism by
936936
introducing the status parameter in the Mobile Security Object (MSO)
@@ -1151,9 +1151,7 @@ d2 # tag(18)
11511151

11521152
A response MAY also choose to redirect the client to another URI
11531153
using an HTTP status code in the 3xx range, which clients SHOULD
1154-
follow. A client SHOULD detect and intervene in cyclical
1155-
redirections (i.e., "infinite" redirection loops). See Section 11.4
1156-
for further guidance on redirects.
1154+
follow. See Section 11.4 for security considerations on redirects.
11571155

11581156
The following are non-normative examples of a request and response
11591157
for a Status List Token with type application/statuslist+jwt:
@@ -1169,8 +1167,8 @@ d2 # tag(18)
11691167
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
11701168
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
11711169
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
1172-
nR0bCI6NDMyMDB9.8ZzvWsUWWvdRDW2quZcLlj28y8Je3ejw20EqLk662ssZb9rwlnuA
1173-
gjjtBYBIIkv0VMUxaqQ_OL3CTmJZaDMkiw
1170+
nR0bCI6NDMyMDB9.y_p6jeXfKQyeXc0kYSSTT6guxCX88eqZscMmiHDRphWOZxA9XCtY
1171+
gqUjP-uw8LVaWZiymuRpbEwF_C0t5rxaDA
11741172

11751173
8.2. Status List Response
11761174

@@ -1318,8 +1316,8 @@ d2 # tag(18)
13181316
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
13191317
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
13201318
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
1321-
nR0bCI6NDMyMDB9.8ZzvWsUWWvdRDW2quZcLlj28y8Je3ejw20EqLk662ssZb9rwlnuA
1322-
gjjtBYBIIkv0VMUxaqQ_OL3CTmJZaDMkiw
1319+
nR0bCI6NDMyMDB9.y_p6jeXfKQyeXc0kYSSTT6guxCX88eqZscMmiHDRphWOZxA9XCtY
1320+
gqUjP-uw8LVaWZiymuRpbEwF_C0t5rxaDA
13231321

13241322
9. Status List Aggregation
13251323

@@ -1536,18 +1534,20 @@ d2 # tag(18)
15361534
Clients that follow 3xx (Redirection) class of status codes should be
15371535
aware of possible dangers of redirects, such as infinite redirection
15381536
loops since they could be used as an attack vector for possible
1539-
denial of service attacks on clients. The general guidance for
1540-
redirects given in Section 15.4 of [RFC9110] should be applied.
1537+
denial of service attacks on clients. A client SHOULD detect and
1538+
intervene in cyclical redirections (i.e., "infinite" redirection
1539+
loops). More guidance for redirects given in Section 15.4 of
1540+
[RFC9110] should be applied.
15411541

15421542
11.5. Exiration and Caching
15431543

15441544
Expiration and Caching information is conveyed via the exp and ttl
15451545
claims as explained in Section 13.7. Clients should check that both
15461546
values are within reasonable ranges before requesting new Status List
15471547
Tokens based on these values to prevent accidentally creating
1548-
unreasonable amounts of requests for a specific URL. Status Provider
1548+
unreasonable amounts of requests for a specific URL. Status Issuers
15491549
could accidentally or maliciously use this mechanism to effectively
1550-
DDoS the provided Status List Token URI.
1550+
DDoS the contained URL of the Status Provider.
15511551

15521552
Concrete values for both claims heavily depend on the use-case
15531553
requirements and clients should be configured with lower/upper bounds

0 commit comments

Comments
 (0)