Re: [OAUTH-WG] New OAuth DPoP and Security BCP drafts

2019-08-01 Thread Sascha Preibisch
Hi all! I am reading through the latest draft ( ... dpop-02). When I got to the first example request (bullet 5.) I saw that only 'grant_type, code, redirect_uri' are used. If I am not mistaken the recommendation is to generally use PKCE with an authorization_code flow. Therefore, I wondered if t

[OAUTH-WG] I-D Action: draft-ietf-oauth-reciprocal-04.txt

2019-08-01 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : Reciprocal OAuth Author : Dick Hardt Filename: draft-ietf-oauth-reciprocal-04.txt