diff --git a/1.1/openid-4-verifiable-credential-issuance-1_1.md b/1.1/openid-4-verifiable-credential-issuance-1_1.md index 5065b53f..f0047db2 100644 --- a/1.1/openid-4-verifiable-credential-issuance-1_1.md +++ b/1.1/openid-4-verifiable-credential-issuance-1_1.md @@ -913,6 +913,7 @@ If the type is `urn:openid:dcp:ia:auth_via_web`, the Authorization Server is ind In this case, the Authorization server MUST include the key `request_uri` in the response. The Wallet MUST use the `request_uri` value to build an Authorization Request as defined in Section 4 of [@!RFC9126] and complete the rest of the authorization process as defined there. The Wallet MUST only use a `request_uri` value once. +If the Wallet supports multiple concurrent sessions, it MUST include the `state` parameter in the Authorization Request so it can identify the session that the redirect from the Authorization Server belongs to. Authorization servers SHOULD treat `request_uri` values as one-time use but MAY allow for duplicate requests due to a user reloading/refreshing their user agent. An expired request_uri MUST be rejected as invalid. The Authorization Server MAY include the `expires_in` key as defined in [@!RFC9126]. @@ -952,6 +953,8 @@ Additional, custom types of interactions MAY be defined by extensions of this sp It is RECOMMENDED to use this extension point instead of modifying the OAuth protocol in order to facilitate interactions that require interactions with native components of the Wallet application. See (#ia-security) for additional security considerations. +Custom interaction types SHOULD, if relevant, define how a Wallet supporting multiple concurrent sessions binds any external communication to the correct session. + In the following non-normative example, this extension point is used to read the Betelgeuse Intergalactic ID card through an NFC interface in the Wallet. A token called `biic_token` is used to start the process. ```