Re: [OAUTH-WG] OAuth Interim Meetings

2021-09-04 Thread Aaron Parecki
I would like to present on OAuth 2.1. Separately, and preferably later in the series, I would like to present on the Browser App BCP. Thanks! Aaron On Sat, Sep 4, 2021 at 8:23 AM Rifaat Shekh-Yusef wrote: > All, > > We would like to start a new series of interim meetings later in September.

Re: [OAUTH-WG] OAuth Interim Meetings

2021-09-04 Thread Justin Richer
I would like to present the proposed HTTP signatures draft, and separately I think it would also be beneficial to the OAuth wg to present an update on the progress of GNAP. -Justin From: OAuth [oauth-boun...@ietf.org] on behalf of Rifaat Shekh-Yusef [ri

[OAUTH-WG] Spam apparently coming from my email address

2021-09-04 Thread Thomas Broyer
Hi all, Someone's apparently sending spam through this list using my email address as the sender. I'm obviously not the author of those. Could some of you please send me the full spam mail (with full mail headers) ? Thank you in advance and sorry for the inconvenience but I don't think I can do

[OAUTH-WG] OAuth Interim Meetings

2021-09-04 Thread Rifaat Shekh-Yusef
All, We would like to start a new series of interim meetings later in September. Please, let us know if you would like to present during one of these meetings. Regards, Rifaat & Hannes ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/

[OAUTH-WG] IPR Disclosures - OAuth 2.0 Authorization Server Issuer Identification

2021-09-04 Thread Rifaat Shekh-Yusef
Authors, As part of the shepherd write-up, all authors of the document must confirm that any and all appropriate IPR disclosures required for full conformance with the provisions of BCP 78 and BCP 79 have already been filed. Please, reply to this email on the mailing list and indicate if you are

[OAUTH-WG] Implementations for OAuth 2.0 Authorization Server Issuer Identification

2021-09-04 Thread Rifaat Shekh-Yusef
All, As part of the shepherd write-up for the OAuth 2.0 Authorization Server Issuer Identification document, we need a list of implementations for this specification. Please, reply to this email on the list with any implementation details for this document. Regards, Rifaat _

[OAUTH-WG] Doc Shepherd Review - OAuth 2.0 Authorization Server Issuer Identification

2021-09-04 Thread Rifaat Shekh-Yusef
Hi Karsten, Daniel, As the document shepherd, I have reviewed the document and I have the following comments on draft-ietf-oauth-iss-auth-resp-01 version: Section 2.4, paragraph 3, first sentence: "If clients interact with both authorization servers supporting this specification and authoriz

[OAUTH-WG] I-D Action: draft-ietf-oauth-jwt-introspection-response-12.txt

2021-09-04 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : JWT Response for OAuth Token Introspection Authors : Torsten Lodderstedt

Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-04 Thread Torsten Lodderstedt
The AS intentionally shares the list of accounts in the mentioned example with the client. The assumption is the client asks for access to some accounts and the user decides which accounts to grant the client access to. This means the AS is authorized by the user to share this data. The privacy