Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion API-strategie-modules/access-control/access-control.md
Original file line number Diff line number Diff line change
Expand Up @@ -364,7 +364,8 @@ The [Forum Standaardisatie Comply-Or-Explain-List](https://www.forumstandaardisa

The following guidelines should be used to select the appropriate standard for a specific context:

1. In the use case a User/Resource owner gives consent to a third-party to access Data
0. In the use case a citizen wants to login to a government service provider the service provider MUST provide a login service compatible with NL GOV Assurance Profile for OAuth 2.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deze paragraaf is bedoeld als toelichting op de geldende spelregels obv toepassingsgebied van de standaarden op de PTLU lijst;
Volgt deze login regel ook uit de PTLU lijst?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
0. In the use case a citizen wants to login to a government service provider the service provider MUST provide a login service compatible with NL GOV Assurance Profile for OAuth 2.0
0. In the use case a citizen wants to log in to a government service provider the service provider MUST provide a login service compatible with NL GOV Assurance Profile for OAuth 2.0

1. 1. In the use case a User/Resource owner gives consent to a third-party to access Data
* YES → NL GOV Assurance Profile for OAuth 2.0
* NO → go to 2
2. In the use case, data exchange occurs with General Digital Infrastructure (GDI) central systems (e.g., base registries), cross-sectoral between organizations, or requires mutual (two-way) authentication.
Expand Down