The OAuth Authorization Server Metadata specification has been updated to
incorporate feedback received during IETF last call. Thanks to Shwetha
Bhandari, Brian Carpenter, Donald Eastlake, Dick Hardt, and Mark Nottingham for
their reviews. See the Document History appendix for clarifications a
Title : OAuth 2.0 Authorization Server Metadata
Authors : Michael B. Jones
Nat Sa
And, for what it's worth, here's the (poorly named) resource indicators
draft that was mentioned during the same discussion.
> I just revved the expired and archived dra
Comments on draft-ietf-oauth-security-topics-04
1. Section 2.2 states:
2.2. Token Leakage Prevention
Authorization servers _*shall*_ use TLS-based methods for sender
constraint access tokens as described in section Section,
such as token binding [I-D.ietf-oauth-t
I just revved the expired and archived draft so that it will be easier for
discussion around draft-hardt-oauth-distributed .
This is the draft I mentioned during the meeting. Previous versions had
JSON response as "_links" as well.
