Re: [OAUTH-WG] PAR: pushed requests must become JWTs

2020-01-08 Thread Torsten Lodderstedt
Hi, you are right, PAR does not require the AS to represent the request as a JWT-based request object. The URI is used as internal reference only. That why the draft states "There is no need to make the authorization request data available to other parties via this URI.” This dif

Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: [UNVERIFIED SENDER] Re: [UNVERIFIED SENDER] Re: PAR metadata

2020-01-08 Thread Richard Backman, Annabelle
I almost included text to that effect, but thought it was getting too wordy. However your suggestion is simple and concise. +1 Given all of this discussion, we should include a section on request validation in Security Considerations, to provide some context on what might be validated when and

Re: [OAUTH-WG] Call for Adoption: OAuth 2.0 Rich Authorization Requests

2020-01-08 Thread Dave Tonge
+1 On Wed, 8 Jan 2020 at 14:30, Nat Sakimura wrote: > +1 > > On Wed, Jan 8, 2020 at 8:53 AM Joseph Heenan wrote: > >> +1 >> >> On 8 Jan 2020, at 03:31, Steinar Noem wrote: >> >> +1 >> >> tir. 7. jan. 2020 kl. 17:53 skrev Torsten Lodderstedt > 40lodderstedt@dmarc.ietf.org <40lodderstedt

Re: [OAUTH-WG] Call for Adoption: OAuth 2.0 Rich Authorization Requests

2020-01-08 Thread Nat Sakimura
+1 On Wed, Jan 8, 2020 at 8:53 AM Joseph Heenan wrote: > +1 > > On 8 Jan 2020, at 03:31, Steinar Noem wrote: > > +1 > > tir. 7. jan. 2020 kl. 17:53 skrev Torsten Lodderstedt 40lodderstedt@dmarc.ietf.org <40lodderstedt@dmarc.ietf..org>>: > >> +1 >> >> > On 7. Jan 2020, at 17:25, Brian C

Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: [UNVERIFIED SENDER] Re: PAR metadata

2020-01-08 Thread Torsten Lodderstedt
Hi Annabelle, thanks for your proposal, which reads reasonable to me. I suggest to extend “and that the request has not been modified in a way that would affect the outcome of the omitted steps.” a bit to also consider policy changes that may have occurred between push and authorization reque

Re: [OAUTH-WG] OAuth@ietf.org mailing list reminder

2020-01-08 Thread kimoun905=40yahoo . com
On Wednesday, January 8, 2020, 2:59:06 PM GMT+7, wrote: You, or someone posing as you, has requested a password reminder for your membership on the mailing list oauth@ietf.org.  You will need this password in order to change your membership options (e.g. do you want regular delivery o