Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

clarify introduction and scope #529

Merged
merged 1 commit into from
Feb 10, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 7 additions & 4 deletions draft-ietf-gnap-core-protocol.md
Original file line number Diff line number Diff line change
Expand Up @@ -158,8 +158,11 @@ passed directly to the software.
# Introduction

This protocol allows a piece of software, the client instance, to request delegated
authorization to resource servers and subject information. This delegation is
facilitated by an authorization server usually on
authorization to resource servers and subject information. The delegated access to
the resource server can be used by the client instance to access resources and APIs
on behalf a resource owner, and delegated access to
subject information can in turn be used by the client instance to make authentication decisions.
This delegation is facilitated by an authorization server usually on
behalf of a resource owner. The end user operating the software can interact
with the authorization server to authenticate, provide consent, and
authorize the request as a resource owner.
Expand Down Expand Up @@ -312,10 +315,10 @@ Right:
: ability given to a subject to perform a given operation on a resource under the control of an RS.

Subject:
: person, organization or device. The subject decides whether and under which conditions its attributes can be disclosed to other parties.
: person or organization. The subject decides whether and under which conditions its attributes can be disclosed to other parties.

Subject Information:
: set of statements and attributes asserted by an AS about a subject.
: set of statements and attributes asserted by an AS about a subject. These statements can be used by the client instance as part of an authentication decision.



Expand Down
Loading