Re: [OAUTH-WG] Error code for access token request

2012-01-19 Thread Eran Hammer
In the case of section 5, because this is a direct interaction with the client, the server should issue a 5xx response instead. EHL From: Antonio Sanso [mailto:asa...@adobe.com] Sent: Thursday, January 19, 2012 9:06 AM To: Eran Hammer Cc: OAuth WG Subject: Re: Error code for access token reques

Re: [OAUTH-WG] Access Token Response without expires_in

2012-01-19 Thread Justin Richer
Precisely, and without a strong consensus of use in practice today, getting the semantics right around a new parameter (even if optional) doesn't make sense this late in the game. The information in the token response is easily extensible by other documents, and it should go there if people rea

Re: [OAUTH-WG] Error code for access token request

2012-01-19 Thread Antonio Sanso
Hi Eran, thanks a lot for your response. As long as I understood from [1] though the error parameter is mandatory error REQUIRED. A single error code from the following: Which one is appropriate in case of server error? I cannot see any that would suite... Thanks in advance Antoni

[OAUTH-WG] Fwd: Smart Object Security Workshop Announcement

2012-01-19 Thread Hannes Tschofenig
Hi all, I know that a few of you have integrated OAuth into small devices, like picture frames. It would be great if you could share your experience about the utilized security mechanisms with us. Ciao Hannes Begin forwarded message: > From: Hannes Tschofenig > Date: January 19, 2012 12:2