(restarting discussion from
http://groups.google.com/group/oauth-ietf-wg/browse_thread/thread/8aeb31817ead4c2a/f19773643e0a8ba3?pli=1
with matching subject)
Given the practice that the authorization endpoint and the redirect_uri can
contain URI query parameters, then differentiating between application specific
query parameters and OAuth protocol parameters by prefixing the OAuth
parameters with oauth_ would seem a useful way to minimize conflicts.
Since calls to the token endpoint use POST, there can not be any confusion
between the parameters in the body of the message and URI query parameters
Note this has nothing to do with differentiating between protocol extension
parameters and core OAuth parameters.
-- Dick
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth