Hi John,
- new audience header
Why do you want to use another header/parameter to identify the target
RS? Isn't scope sufficient to carry this information?
The text seems to be inconsistent regarding the name (aud or audience)
and whether this is actually an header or a parameter.
I also miss the header/parameter in the example request.
- alg
I assume the client is supposed to first discovers the RS's
capabilities. Any idea how the client should do this?
kind regards,
Torsten.
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth