Re: [OAUTH-WG] Clarifying the scope of the OAuth 2.1 spec (Mike Jones)

2020-03-16 Thread Lee McGovern
The statement "removing features that are not currently considered to be best practices" is ambiguous and implies that the best practise could be reinterpreted to include the flows that are now being deprecated. Perhaps "removing features that are no longer considered to be best practices" is mu

Re: [OAUTH-WG] OAuth Digest, Vol 136, Issue 31

2020-02-25 Thread Lee McGovern
I agree with Bruno and Dick regarding version compliance -Original Message- From: OAuth On Behalf Of oauth-requ...@ietf.org Sent: Dienstag, 25. Februar 2020 01:56 To: oauth@ietf.org Subject: OAuth Digest, Vol 136, Issue 31 Send OAuth mailing list submissions to oauth@ietf.org To

Re: [OAUTH-WG] WGLC for "OAuth 2.0 Security Best Current Practice"

2019-11-10 Thread Lee McGovern
3.1 - "Clients MUST memorize which authorization server they sent an authorization request to" - is memorize the best synonym here, perhaps store or retain is more aligned with computational language? 3.1.2 How does the draft https://tools.ietf.org/html/draft-parecki-oauth-browser-based-apps-

[OAUTH-WG] Security BCP Review

2019-11-05 Thread Lee McGovern
As discussed on call yesterday here is my comments after review of https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13 3.1 - "Clients MUST memorize which authorization server they sent an authorization request to" - is memorize the best synonym here, perhaps store or retain is more

[OAUTH-WG] Virtual Office Hours

2019-10-16 Thread Lee McGovern
How does a newcomer get the meeting invite/dial in info for this call? This e-mail, including attachments, is intended for the person(s) or company named and may contain confidential and/or legally privileged information. Unauthorized disclosure, copying or use of this information may be unlawf

[OAUTH-WG] OBO Flow

2019-07-08 Thread Lee McGovern
. when Yelp wants access to your Google contacts a scope is defined and consent is granted for that client to act on your behalf... Best, Lee McGovern | IAM Architect | lee_mcgov...@swissre.com<mailto:lee_mcgov...@swissre.com> This e-mail, including attachments, is intended for the pe