Re: [OAUTH-WG] Authorization code use in draft-ietf-oauth-v2-21

2011-09-20 Thread Eran Hammer-Lahav
> On Sep 9, 2011, at 15:31, "André DeMarre" > wrote: > > > Greetings Everyone, > > > > I hope the draft isn't too far along for these comments. > > (draft-ietf-oauth-v2-21) > > > > 1. AUTHORIZATION CODE RESTRICTIONS > > > > The specification (particularly Section 4.1) does not say if the > > au

Re: [OAUTH-WG] Authorization code use in draft-ietf-oauth-v2-21

2011-09-12 Thread André DeMarre
I overlooked section 10.5 paragraph 3, which addresses my first point below, but I think enforcing single use authentication codes should also be included at the bottom of section 4.1.3 in the "authorization server MUST" list. Proposed text for item 3: "verify that the authorization code is valid a

Re: [OAUTH-WG] Authorization code use in draft-ietf-oauth-v2-21

2011-09-09 Thread Eran Hammer-Lahav
Sending to the right address. EHL On Sep 9, 2011, at 15:31, "André DeMarre" wrote: > Greetings Everyone, > > I hope the draft isn't too far along for these comments. > (draft-ietf-oauth-v2-21) > > 1. AUTHORIZATION CODE RESTRICTIONS > > The specification (particularly Section 4.1) does not s