Thank you for the comments, Roman.
Thank you for your suggestion, Warren.
I prefer Roman's solution because I'd like to keep the
policy/configuration/scenario part. I think it helps to explain _why_
these decisions are out of the scope for this specification.
Best regards,
Karsten
On 27.10.
Would making it even simpler also work? (and is more consistent with the
6749 language)
>
> The decision of whether to accept such responses is beyond the scope of
> this specification.
Warren Parad
Founder, CTO
Secure your user data with IAM authorization as a service. Implement
Authress
Hi!
I performed an AD review of draft-ietf-oauth-iss-auth-resp-02. Thanks for
documenting this mitigation.
The document is in good shape so I am advancing it to IETF LC. Please treat
these minor comments as part of that feedback:
** Section 2.4. Editorial.
The decision of whether to a