Dear Eran,

I'm still hoping you will consider adding back the MAC spec a
requirement for a body hash covered by the MAC.  I still also feel
that the lack of a hash covered by the MAC that protects the value of
the response and response body makes this proposed spec quite a bit
weaker than it should ideally be.

You mentioned in arguing that there can be operational issues with
verifying the body hash that intermediaries may transform the body.
However, the HTTP 1.1 spec at least includes a header that seems
designed specifically to mitigate at least the concerns about
transformation of the body: Cache-Control: no-transform

This header should be respected by well-behaved proxies. e.g. see:

It would seem that by including this header in the Oauth2 MAC spec for
the request and the response there should not be operational issues
with verifying a hash of the content?



On Wed, Feb 8, 2012 at 5:59 PM, Eran Hammer <> wrote:
> New draft:
> EH
OAuth mailing list

Reply via email to