Skip to content

Commit 9711d2d

Browse files
authored
docs: reconcile ARCHITECTURE RFC table with code (P2-3) (#16)
The RFC/standards table omitted two RFCs the code actually anchors to: - crypto: RFC 8785 (JSON Canonicalization Scheme) — 3 refs in packages/crypto/src. - jwt: RFC 6749 (OAuth 2.0, refresh-reuse detection per §10.4) — 3 refs in packages/jwt/src. Also mark the not-yet-shipped rows (jwe, paseto, oauth2, oidc) as _(planned)_ so the table matches the stack table's shipped/planned split. Verified: the RFCs jwt's README additionally names (7662 / 9101 / 9449) are NOT referenced in src, so the table correctly still omits them; apikey / challenge / ua cite no RFCs, so they get no row. Refs #11 (P2-3).
1 parent 6065e94 commit 9711d2d

1 file changed

Lines changed: 6 additions & 6 deletions

File tree

‎ARCHITECTURE.md‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -233,20 +233,20 @@ Where each protocol is anchored:
233233

234234
| Package | RFC / spec references |
235235
|-----------------|------------------------------------------------------------------------------|
236-
| `crypto` | NIST SP 800-108 (KDF), NIST SP 800-38D (GCM), RFC 5869 (HKDF), RFC 8018 (PBKDF2) |
236+
| `crypto` | NIST SP 800-108 (KDF), NIST SP 800-38D (GCM), RFC 5869 (HKDF), RFC 8018 (PBKDF2), RFC 8785 (JCS) |
237237
| `password` | Argon2 spec (2015), NIST SP 800-63B §5.1.1, OWASP ASVS V2 |
238238
| `otp` | RFC 4226 (HOTP), RFC 6238 (TOTP), Google Authenticator `otpauth://` URI spec |
239239
| `jwk` | RFC 7517 (JWK), RFC 7518 §6 (JWK parameters), RFC 7638 (thumbprint), RFC 8037 (OKP), RFC 8812 (secp256k1), RFC 9278 (thumbprint URI) |
240240
| `jws` | RFC 7515 (JWS), RFC 7518 §3 (JWA), RFC 7797 (unencoded payload), RFC 8037, RFC 8812, RFC 8725 (BCP) |
241-
| `jwt` | RFC 7519 (JWT), RFC 8725 (BCP), RFC 9068 (JWT profile for OAuth2) |
242-
| `jwe` | RFC 7516 (JWE), RFC 7518 §4 (encryption algorithms), RFC 8037 (X25519 / X448) |
241+
| `jwt` | RFC 6749 §10.4 (refresh reuse), RFC 7519 (JWT), RFC 8725 (BCP), RFC 9068 (JWT profile for OAuth2) |
242+
| `jwe` | _(planned)_ RFC 7516 (JWE), RFC 7518 §4 (encryption algorithms), RFC 8037 (X25519 / X448) |
243243
| `jwks` | RFC 7517 §5 (JWK Set), OpenID Connect Discovery |
244244
| `opaque` | RFC 7662 (Token Introspection), RFC 7009 (Token Revocation) |
245-
| `paseto` | PASETO v4 spec |
245+
| `paseto` | _(planned)_ PASETO v4 spec |
246246
| `session` | OWASP ASVS 4.0.3 V3, RFC 6265 (Cookies) |
247247
| `security` | OWASP ASVS 4.0.3 V13 / V14, RFC 6749 §10 (OAuth2 threats), RFC 7231 §5 (HTTP) |
248-
| `oauth2` | RFC 6749, RFC 7636 (PKCE), RFC 9126 (PAR), RFC 8414 (metadata), RFC 8628 (device)|
249-
| `oidc` | OpenID Connect Core 1.0, OpenID Connect Discovery |
248+
| `oauth2` | _(planned)_ RFC 6749, RFC 7636 (PKCE), RFC 9126 (PAR), RFC 8414 (metadata), RFC 8628 (device) |
249+
| `oidc` | _(planned)_ OpenID Connect Core 1.0, OpenID Connect Discovery |
250250
| `passkey` | W3C WebAuthn Level 3, FIDO2 CTAP2 |
251251

252252
For deeper per-package interface tables (JSDoc typedefs, worked API

0 commit comments

Comments
 (0)