Skip to content

docs: guides to mTLS, Message Signing, CIBA, RAR and OpenID Federation - #549

Merged
osanderson merged 1 commit into
mainfrom
docs/more-guides
Oct 4, 2026
Merged

osanderson merged 1 commit into
mainfrom
docs/more-guides

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

These are five more docs/guides pages in the same form as the DPoP, PAR and native-app guides (#546). Each covers one mechanism across every role involved, and links the demo code that shows it running.

Guide Covers
Mutual TLS in Go Certificate client authentication and certificate-bound tokens (RFC 8705); client and server trust configuration, including CRLs and proxies; the resource server's binding check. The demo is payroll-run.
FAPI 2.0 Message Signing in Go Selecting the profile, signed request objects (JAR) and authorization responses (JARM), and signed UserInfo. The demos are payment-consent and identity-check.
CIBA in Go Poll and ping delivery on the client, and the server's begin, complete and exchange steps. The demo is decoupled-checkout.
Rich Authorization Requests in Go Defining types, per-client types, policies, approving at consent, and reading grants at the resource server. The demos are payment-consent, linked-accounts and decoupled-checkout.
OpenID Federation in Go Publishing an Entity Configuration, automatic client registration, the relying party side, and running a Trust Anchor or Intermediate. The demo is federated-union.

The guides index and the README list all eight guides.

Verification

  • API: every type, field and method comes from the current API.
  • Snippets: every Go snippet type-checks, with typed stand-ins for reader-supplied values. Constructors that could fail at runtime were also run as written:
    • client registrations for each mTLS method;
    • the RAR registry, plus RARSet and RARGet round trips, and case-variant and undeclared members refused;
    • a federation resolver with the guide's limits.
  • Claims: behaviour claims were checked against the code and doc comments. Demo claims (attack names, files, what each shows) were grep-checked. Corrections made while writing:
    • what New enforces under Message Signing;
    • signed UserInfo being a server-wide setting, not per client;
    • the RAR policy wording for client credentials;
    • NoClientCertificateChainTrust's meaning;
    • CIBA's full list of attacks;
    • federation's required FederationHTTP;
    • two link references that never rendered as links.
  • Links: none broken. The identifier scan finds no new unresolved references.

Docs only.

🤖 Generated with Claude Code

Five more docs/guides pages, each covering one mechanism across every
role involved, in the same form as the DPoP, PAR and native app guides:

- Mutual TLS in Go: certificate client authentication and
  certificate-bound tokens, client and server trust configuration,
  proxies, and the resource server's binding check.
- FAPI 2.0 Message Signing in Go: selecting the profile, signed request
  objects and authorization responses, and signed UserInfo.
- CIBA in Go: poll and ping delivery on the client, and the server's
  begin, complete and exchange steps.
- Rich Authorization Requests in Go: defining types, per-client types,
  policies, approving at consent, and reading grants at the resource
  server.
- OpenID Federation in Go: publishing an Entity Configuration, automatic
  client registration, the relying party side, and running a Trust
  Anchor or Intermediate.

Each links the demo code that shows it running. The guides index and
the README list all eight.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@osanderson
osanderson merged commit f4e0f70 into main Oct 4, 2026
17 checks passed
@osanderson
osanderson deleted the docs/more-guides branch October 4, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant