Thanks, I fixed my finger dyslexia for the next draft. I changed it to t_m rather than âtâ I think that is clearer. If I were to do it the other way XML2RFC would have double quotes in the text version.
John B. > On Jul 7, 2015, at 9:38 PM, William Denniss <wdenn...@google.com> wrote: > > In version 14, there's a typo on this line ("deso") in Section 7.2: > > `"plain" method deso not protect` > > Also, in the 1.1 Protocol Flow diagram, regarding the text: > > `+ t(code_verifier), t` > > I wonder if it makes more sense to represent as `+ t(code_verifier), "t"` > (note the quotes on the second 't') given that it's a string representation > of the method that's being sent? > > > On Mon, Jul 6, 2015 at 4:05 PM, <internet-dra...@ietf.org > <mailto:internet-dra...@ietf.org>> wrote: > > A New Internet-Draft is available from the on-line Internet-Drafts > directories. > This draft is a work item of the Web Authorization Protocol Working Group of > the IETF. > > Title : Proof Key for Code Exchange by OAuth Public Clients > Authors : Nat Sakimura > John Bradley > Naveen Agarwal > Filename : draft-ietf-oauth-spop-14.txt > Pages : 20 > Date : 2015-07-06 > > Abstract: > OAuth 2.0 public clients utilizing the Authorization Code Grant are > susceptible to the authorization code interception attack. This > specification describes the attack as well as a technique to mitigate > against the threat through the use of Proof Key for Code Exchange > (PKCE, pronounced "pixy"). > > > The IETF datatracker status page for this draft is: > https://datatracker.ietf.org/doc/draft-ietf-oauth-spop/ > <https://datatracker.ietf.org/doc/draft-ietf-oauth-spop/> > > There's also a htmlized version available at: > https://tools.ietf.org/html/draft-ietf-oauth-spop-14 > <https://tools.ietf.org/html/draft-ietf-oauth-spop-14> > > A diff from the previous version is available at: > https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-spop-14 > <https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-spop-14> > > > Please note that it may take a couple of minutes from the time of submission > until the htmlized version and diff are available at tools.ietf.org > <http://tools.ietf.org/>. > > Internet-Drafts are also available by anonymous FTP at: > ftp://ftp.ietf.org/internet-drafts/ <ftp://ftp.ietf.org/internet-drafts/> > > _______________________________________________ > OAuth mailing list > OAuth@ietf.org <mailto:OAuth@ietf.org> > https://www.ietf.org/mailman/listinfo/oauth > <https://www.ietf.org/mailman/listinfo/oauth> > > _______________________________________________ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth
_______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth