The Apr 11 ad hoc (which was quorate) worked through#294 (Consider a proof-of-possession option for the RPT)
Concrete proposal for spec refactoring (#290 (Generality of RReg spec?) and #296 (Out-of-the-box profiling for tight AS-RS coupling)) may be ready for consideration in Apr 20 meeting
Let's see if we can work through the rest of the open substantive issues in this meeting
Core is up to 20 and RReg is up to 06 (WG drafts; no change)
#295 (When a requesting party needs to withdraw their access): This touches on downscoping and token revocation, and thus could use some analysis
#298 (Reconsider whether ticket should be on all redirect-back AS responses): Main issue seems to need no action, but a related issue came up about the appropriateness of not_authorized as an error that we could consider
#303 (Cleaning up the security considerations: JSON Usage): Possibly pass a quick eye over this one