Re: [OAUTH-WG] Comments on OAuth 2.0 Bearer Token specification draft -01

2011-01-14 Thread Mike Jones
Thanks for your comments, Torsten. I've removed the sentence "Encrypting the token contents is another alternative ..." from draft -02 since it was redundant and potentially confusing. I deleted the word "rare", since I agree with your conclusion. The "reuse" phrase now reads: "To deal with to

[OAUTH-WG] Comments on OAuth 2.0 Bearer Token specification draft -01

2011-01-10 Thread Torsten Lodderstedt
Hi Mike, I've got some more comments on ยง 3.2 of your I-D. paragraph 4: "Encrypting the token contents is another alternative ..." How does token content encryption prevent the disclosure and abuse of a token? paragraph 5: "For those rare cases where the client is prevented from observing th