[OAUTH-WG] Preventing use of a constant PKCE challenge value

2023-12-18 Thread Michael Jones
Hi all, I filed https://github.com/oauthstuff/draft-ietf-oauth-security-topics/pull/86 as a result of discussions at IETF in Prague but it seems to have stalled. What text are we going to add to draft-ietf-oauth-security-topics to prevent use of a constant PKCE challenge value, if not that pro

[OAUTH-WG] AD Review of draft-ietf-oauth-security-topics-24

2023-12-18 Thread Roman Danyliw
Hi! I performed an AD review of draft-ietf-oauth-security-topics-24. Thank you for taking the time to document many years of operational deployment experience. My feedback is below: From idnits: ** All documents that are called out as being updated in the meta-data need to be mentioned in th