RFC 9126 - OAuth 2.0 Pushed Authorization Requests (PAR)
- ステータス: Proposed Standard
- 発行日: September 2021
- ストリーム: IETF
- エラッタ: エラッタなし
## Abstract (概要)
本ドキュメントは pushed authorization request (PAR) エンドポイントを定義する. クライアントは OAuth 2.0 認可リクエストのペイロードを直接リクエストで認可サーバへプッシュでき, 返却された request URI を後続の認可エンドポイント呼び出しでデータを参照するために用いる.
***
## Status of This Memo (本メモの状態)
本ドキュメントは Internet Standards Track に属する.
Internet Engineering Task Force (IETF) の成果物であり IETF コミュニティの合意を表す. 公開レビューを経て Internet Engineering Steering Group (IESG) により出版が承認された. Internet Standards についての詳細は RFC 7841 第 2 節を参照.
本ドキュメントの現状, 正誤表, フィードバック方法は ``https://www.rfc-editor.org/info/rfc9126`` を参照.
***
## Copyright Notice (著作権表示)
Copyright (c) 2021 IETF Trust および文書に記載の著者. 無断転載を禁ずる.
本ドキュメントは BCP 78 および IETF Trust の IETF 文書に関する Legal Provisions (``https://trustee.ietf.org/license-info``) の対象であり, 発行日時点で有効な条項が適用される. 利用者の権利と制限については当該文書を確認すること. 本ドキュメントから抽出したコードコンポーネントには Trust Legal Provisions 第 4.e 節に記載の Simplified BSD License 文を含めなければならず, Simplified BSD License に従い無保証で提供される.
***
## Contents (目次)
- [1. Introduction (はじめに)](/rfc-9126/1-introduction)
- [1.1. Introductory Example (導入例)](/rfc-9126/1-1-introductory-example)
- [1.2. Conventions and Terminology (表記規則と用語)](/rfc-9126/1-2-conventions-and-terminology)
- [2. Pushed Authorization Request Endpoint (PAR エンドポイント)](/rfc-9126/2-pushed-authorization-request-endpoint)
- [2.1. Request (リクエスト)](/rfc-9126/2-1-request)
- [2.2. Successful Response (成功レスポンス)](/rfc-9126/2-2-successful-response)
- [2.3. Error Response (エラーレスポンス)](/rfc-9126/2-3-error-response)
- [2.4. Management of Client Redirect URIs (クライアントリダイレクト URI の管理)](/rfc-9126/2-4-management-of-client-redirect-uris)
- [3. The "request" Request Parameter ("request" リクエストパラメータ)](/rfc-9126/3-the-request-request-parameter)
- [4. Authorization Request (認可リクエスト)](/rfc-9126/4-authorization-request)
- [5. Authorization Server Metadata (認可サーバメタデータ)](/rfc-9126/5-authorization-server-metadata)
- [6. Client Metadata (クライアントメタデータ)](/rfc-9126/6-client-metadata)
- [7. Security Considerations (セキュリティ上の考慮事項)](/rfc-9126/7-security-considerations)
- [7.1. Request URI Guessing (リクエスト URI の推測)](/rfc-9126/7-1-request-uri-guessing)
- [7.2. Open Redirection (オープンリダイレクト)](/rfc-9126/7-2-open-redirection)
- [7.3. Request Object Replay (リクエストオブジェクトのリプレイ)](/rfc-9126/7-3-request-object-replay)
- [7.4. Client Policy Change (クライアントポリシーの変更)](/rfc-9126/7-4-client-policy-change)
- [7.5. Request URI Swapping (リクエスト URI のすり替え)](/rfc-9126/7-5-request-uri-swapping)
- [8. Privacy Considerations (プライバシー上の考慮事項)](/rfc-9126/8-privacy-considerations)
- [9. IANA Considerations (IANA に関する考慮事項)](/rfc-9126/9-iana-considerations)
- [9.1. OAuth Authorization Server Metadata](/rfc-9126/9-1-oauth-authorization-server-metadata)
- [9.2. OAuth Dynamic Client Registration Metadata](/rfc-9126/9-2-oauth-dynamic-client-registration-metadata)
- [9.3. OAuth URI Registration](/rfc-9126/9-3-oauth-uri-registration)
- [10. References (参考文献)](/rfc-9126/10-references)
- [10.1. Normative References (規範的参考文献)](/rfc-9126/10-1-normative-references)
- [10.2. Informative References (参考的参考文献)](/rfc-9126/10-2-informative-references)
- [Acknowledgements (謝辞)](/rfc-9126/acknowledgements)
- [Authors' Addresses (著者連絡先)](/rfc-9126/authors-addresses)
***
## Related Resources (関連リソース)
- **公式テキスト**: [RFC 9126 (TXT)](https://www.rfc-editor.org/rfc/rfc9126.txt)
- **DataTracker**: [RFC 9126](https://datatracker.ietf.org/doc/html/rfc9126)
- **情報ページ**: [RFC Editor](https://www.rfc-editor.org/info/rfc9126)