Rename Issuance Initiation `issuer` parameter to `iss`
Issue #1598
closed
Invocations of the Issuance Initiation Endpoint (potentially via a redirect) require a parameter called issuer
, identifying the OP. There is a similar parameter for Authorization Responses defined in RFC 9207: iss
While the use case there is slightly different (prevent mix-up attacks), I think we should use one parameter name consistently to simplify the spec.
Comments (3)
-
-
agreed to Mike’s comments.
-
- changed status to closed
Closing.
- Log in to comment
The
iss
claim is already defined for use in OAuth requests - see https://www.ietf.org/rfc/rfc9101.html#name-request-object-2. We cannot overloadiss
with two meanings.I believe that this issue should be closed on this basis.