{"repo":"w3c/webappsec-dbsc","summary":{"retrieved":"2026-05-16T07:47:31Z","triageViolations":7,"urgentViolations":0,"soonViolations":0,"agendaViolations":0,"needsEditsViolations":0,"needTriage":0,"urgent":0,"soon":0,"agenda":0,"needsEdits":0,"other":17},"triage":[{"number":176,"url":"https://github.com/w3c/webappsec-dbsc/issues/176","title":"JS bindings for session registration","author":"drubery","createdAt":"2025-05-12T17:29:13Z","labels":[],"sloTimeUsed":"P368DT14H18M18S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":177,"url":"https://github.com/w3c/webappsec-dbsc/issues/177","title":"JS bindings for usage of session keys","author":"drubery","createdAt":"2025-05-12T18:18:47Z","labels":[],"sloTimeUsed":"P368DT13H28M44S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":211,"url":"https://github.com/w3c/webappsec-dbsc/issues/211","title":"Evaluate new possible credential types","author":"drubery","createdAt":"2025-08-15T21:06:50Z","labels":[],"sloTimeUsed":"P273DT10H40M41S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":227,"url":"https://github.com/w3c/webappsec-dbsc/issues/227","title":"Changing which cookies are bound can be complex","author":"drubery","createdAt":"2025-10-01T18:08:11Z","labels":[],"sloTimeUsed":"P226DT13H39M20S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":234,"url":"https://github.com/w3c/webappsec-dbsc/issues/234","title":"Partitioned cookie support","author":"drubery","createdAt":"2025-11-13T06:28:38Z","labels":[],"sloTimeUsed":"P184DT1H18M53S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":255,"url":"https://github.com/w3c/webappsec-dbsc/issues/255","title":"Prevent risk of deadlock during session refresh","author":"alexilin92","createdAt":"2026-04-15T16:28:40Z","labels":[],"sloTimeUsed":"P30DT15H18M51S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":259,"url":"https://github.com/w3c/webappsec-dbsc/issues/259","title":"What should happen to RPs DBSC sessions when the SP session is terminated?","author":"adeinega","createdAt":"2026-05-05T23:30:13Z","labels":[],"sloTimeUsed":"P10DT8H17M18S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true}],"urgent":[],"soon":[],"agenda":[],"needsEdits":[],"other":[{"number":12,"url":"https://github.com/w3c/webappsec-dbsc/issues/12","title":"The scheme is a little bit redundant for a redirect-based auth","author":"alextok","createdAt":"2024-01-04T21:01:18Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":13,"numLabels":0}},{"number":23,"url":"https://github.com/w3c/webappsec-dbsc/issues/23","title":"Require request signing for proof-of-possession","author":"joaopenteado","createdAt":"2024-04-04T10:11:16Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":18,"numLabels":0}},{"number":24,"url":"https://github.com/w3c/webappsec-dbsc/issues/24","title":"Question RE: Tracking and Identity Providers","author":"whitehatguy","createdAt":"2024-04-04T13:35:59Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":31,"url":"https://github.com/w3c/webappsec-dbsc/issues/31","title":"alignment with OAuth 2 flows for 1P authorization servers","author":"dickhardt","createdAt":"2024-04-06T08:33:24Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":33,"url":"https://github.com/w3c/webappsec-dbsc/issues/33","title":"timed refresh mechanism","author":"dickhardt","createdAt":"2024-04-06T08:52:24Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":34,"url":"https://github.com/w3c/webappsec-dbsc/issues/34","title":"Need for attestation?","author":"jackevans43","createdAt":"2024-04-07T12:12:50Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":112,"url":"https://github.com/w3c/webappsec-dbsc/issues/112","title":"HTTP Message Signatures","author":"jricher","createdAt":"2025-03-05T21:54:05Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":7,"numLabels":0}},{"number":117,"url":"https://github.com/w3c/webappsec-dbsc/issues/117","title":"Synchronous operation and capability discovery","author":"sbweeden","createdAt":"2025-03-17T23:53:29Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":152,"url":"https://github.com/w3c/webappsec-dbsc/issues/152","title":"Consider Renaming \"Device Bound Session Credentials\" for Clarity","author":"kkoiwai","createdAt":"2025-04-24T14:36:57Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":210,"url":"https://github.com/w3c/webappsec-dbsc/issues/210","title":"Make challenge lifetime browser-enforced","author":"drubery","createdAt":"2025-08-15T17:28:46Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":223,"url":"https://github.com/w3c/webappsec-dbsc/issues/223","title":"Strategy for rejecting any non compliant DBSC user agent on the server side","author":"reda-alaoui","createdAt":"2025-09-18T16:05:54Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":230,"url":"https://github.com/w3c/webappsec-dbsc/issues/230","title":"Max-Age cookie attribute in JSON session credentials resulting in registration failure","author":"e-aakash","createdAt":"2025-10-30T11:41:35Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":238,"url":"https://github.com/w3c/webappsec-dbsc/issues/238","title":"Alternative short-lived refresh design","author":"martinthomson","createdAt":"2025-11-21T05:20:00Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":3,"numLabels":0}},{"number":243,"url":"https://github.com/w3c/webappsec-dbsc/issues/243","title":"Chrome DBSC: Session marked as session_ended despite valid challenge response","author":"jimmylo16","createdAt":"2026-02-05T12:06:17Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":35,"numLabels":0}},{"number":254,"url":"https://github.com/w3c/webappsec-dbsc/issues/254","title":"Federated sessions (§ 3.3) orthogonal to your stated goals?","author":"maceip","createdAt":"2026-04-14T20:31:35Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":256,"url":"https://github.com/w3c/webappsec-dbsc/issues/256","title":"Estimated Rollout for Android and iOS","author":"invisibleroads","createdAt":"2026-05-01T19:10:07Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":258,"url":"https://github.com/w3c/webappsec-dbsc/issues/258","title":"a session on the RP with the same key","author":"adeinega","createdAt":"2026-05-04T23:11:47Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}}]}