Marius, did you have an alternative to suggest for this?

Not that it has to be in the spec, but it would be nice to have a best practice 
for this as it's a common case.


> On Fri, Jan 28, 2011 at 10:25 AM, Eran Hammer-Lahav <eran at hueniverse.com> 
> wrote:
> > -12 3.1.1:
> >
> >   The redirection URI MUST be an absolute URI and MAY include a query
> >   component, which MUST be retained by the authorization server when
> >   adding additional query parameters.
> >
> > 'oob' is not an absolute URI.
> 
> Good point, I missed the absolute part. Thanks for pointing this out.
> 
> Let me think about it, the URN you suggested is a good start.
> 
> Marius
> 
> From: Marius Scurtescu [mailto:mscurtescu at google.com]
> Sent: Friday, January 28, 2011 10:07 AM
> To: Eran Hammer-Lahav
> Cc: Skylar Woodward; OAuth WG
> Subject: Re: [OAUTH-WG] Native Client Extension
> 
> On Fri, Jan 28, 2011 at 8:21 AM, Eran Hammer-Lahav
> <eran at hueniverse.com> wrote:
> > Why not:
> >
> > urn:ietf:wg:oauth:2.0:oob
> >


_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to