Re: [OAUTH-WG] AD review of draft-ietf-oauth-iss-auth-resp-02

2021-10-28 Thread Karsten Meyer zu Selhausen
Thank you for the comments, Roman. Thank you for your suggestion, Warren. I prefer Roman's solution because I'd like to keep the policy/configuration/scenario part. I think it helps to explain _why_ these decisions are out of the scope for this specification. Best regards, Karsten On 27.10.

Re: [OAUTH-WG] AD review of draft-ietf-oauth-iss-auth-resp-02

2021-10-27 Thread Warren Parad
Would making it even simpler also work? (and is more consistent with the 6749 language) > > The decision of whether to accept such responses is beyond the scope of > this specification. Warren Parad Founder, CTO Secure your user data with IAM authorization as a service. Implement Authress

[OAUTH-WG] AD review of draft-ietf-oauth-iss-auth-resp-02

2021-10-27 Thread Roman Danyliw
Hi! I performed an AD review of draft-ietf-oauth-iss-auth-resp-02. Thanks for documenting this mitigation. The document is in good shape so I am advancing it to IETF LC. Please treat these minor comments as part of that feedback: ** Section 2.4. Editorial. The decision of whether to a