Files
rose-ash/lib/identity/conformance.sh
giles ded7170540
Some checks failed
Test, Build, and Deploy / test-build-deploy (push) Failing after 58s
identity: token exchange — downscope into an independent token (RFC 8693, +8 tests)
oauth.sx gains token_exchange(SubjectToken, RequestedScope): a valid access
token is downscoped into a NEW independent grant for the same subject
(subset only, else invalid_scope; inactive subject token → invalid_grant).
The exchanged token's lifecycle is independent of the subject token
(revoking either leaves the other active); exchanges chain. Least-privilege
handoff to downstream services. New tests/exchange.sx. 201/201.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 03:31:14 +00:00

5.8 KiB
Executable File