Removed 'and lifetime'.

EH

From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of 
Andrew Arnott
Sent: Sunday, February 19, 2012 7:09 AM
To: OAuth WG (oauth@ietf.org)
Subject: [OAUTH-WG] Section 10.3 client advice inapplicable?

>From draft 23, section 10.3:

The client SHOULD request access tokens with the minimal scope and lifetime 
necessary. The authorization server SHOULD take the client identity into 
account when choosing how to honor the requested scope and lifetime, and MAY 
issue an access token with a less rights than requested.

I can't find the part in the spec where the client can request access tokens in 
such a way as to influence the lifetime.  Why is the client then being advised 
in the above section to minimize the lifetime of the access tokens it asks for?

--
Andrew Arnott
"I [may] not agree with what you have to say, but I'll defend to the death your 
right to say it." - S. G. Tallentyre
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to