Draft 19 of the OAuth 2.0 Bearer Token Specification has been published.  
Addressed DISCUSS issues and comments raised for which resolutions have been 
agreed to.  No normative changes were made.  Changes made were:
*         Use ABNF from RFC 5234.
*         Added sentence "The Bearer authentication scheme is intended 
primarily for server authentication using the WWW-Authenticate and 
Authorization HTTP headers, but does not preclude its use for proxy 
authentication" to the introduction.
*         In the introduction, state that this document also imposes semantic 
requirements upon the access token.
*         Reference the scope definition in the OAuth core spec.
*         Added scope examples.
*         Reference RFC 6265 for security considerations about cookies.

The draft is available at:

*         http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer-19
A HTML-formatted version is available at:

*         http://self-issued.info/docs/draft-ietf-oauth-v2-bearer-19.html

                                                                -- Mike

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to