Re: [OAUTH-WG] I-D: multiple access tokens

2010-07-15 Thread Christian Stübner
My post was a reply to http://www.ietf.org/mail-archive/web/oauth/current/msg03639.html. (Something obviously went wrong with the Thread Index.) Regards, Christian > Torsten, > > I came across your I-D when looking for a way to distinguish between > different protected resources. > > Just so

Re: [OAUTH-WG] I-D: multiple access tokens

2010-07-15 Thread Christian Stübner
Torsten, I came across your I-D when looking for a way to distinguish between different protected resources. Just some remarks and questions: o In 3.1. I suppose your example request is missing the service_id, right? o 3.4. Replace server_id by service_id and you comply with the rest of the docu

[OAUTH-WG] OAuth2 Spec Feedback for v2-10

2010-07-15 Thread Christian Stübner
Hi @all! Here is my feedback to the current version (-10) of the draft. So far it looks really promising to me. Just a view thoughts/ideas/questions: 1.4: Is it necessary for an authorization server to support all client profiles in order to be standard complaint? 1.4.1. Wording: Profile "Web S