I think James has made the case that there is an issue clear.

As for what to pick, I favor not restricting scopes in the core spec, and
clearly specifying the way scopes will be presented in HTTP headers in the
bearer spec.

For the later, James supplies a nice list of the alternatives. Personally, I
think the URI-escaping is least likely to trip developers up. One must be
aware, though, that if there is only one scope string to provide, and it
meets the token production, then the scope needn't be in quotes.

I believe RFC 5987 is vast over-kill in this case. We have no need to enable
multiple different encodings, nor multiple encodings with a single header.
Further, I wonder how widespread support for it is in various HTTP
frameworks.

  - Mark
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to