Re: [OAUTH-WG] OAuth Discovery

2015-12-14 Thread Bill Mills
I think it is more likely that the flow for the user will be that they know an RS and the RS provides some reference to the AS.  The RS might well consume a generic lookup flow though.  We do need the "updated webfinger thing" for users as a generic though. The WF type thing for a generic user

[OAUTH-WG] OAuth 2.0 Token Exchange: An STS for the REST of Us

2015-12-14 Thread Mike Jones
I'm happy to report that a substantially revised OAuth 2.0 Token Exchange draft has been published that enables a broad range of use cases, while still remaining as simple as possible. This draft unifies the approaches taken in the previous working group draft and draft-campbell-oauth-sts, inco