Re: [OAUTH-WG] End user auth response code-and-token's scope parameter

2010-07-02 Thread Eran Hammer-Lahav
M To: Eran Hammer-Lahav Cc: OAuth WG (oauth@ietf.org) Subject: Re: [OAUTH-WG] End user auth response code-and-token's scope parameter Ah! Yes I'd missed the second scope parameter that web servers have the opportunity to see. And your point makes sense. Is this reduced scope on the a

Re: [OAUTH-WG] End user auth response code-and-token's scope parameter

2010-07-02 Thread Andrew Arnott
m:* oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] *On Behalf > Of *Andrew Arnott > *Sent:* Friday, July 02, 2010 9:26 AM > *To:* OAuth WG (oauth@ietf.org) > *Subject:* [OAUTH-WG] End user auth response code-and-token's scope > parameter > > > > > >

Re: [OAUTH-WG] End user auth response code-and-token's scope parameter

2010-07-02 Thread Eran Hammer-Lahav
client when using the authorization code and provide greater access. EHL From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Andrew Arnott Sent: Friday, July 02, 2010 9:26 AM To: OAuth WG (oauth@ietf.org) Subject: [OAUTH-WG] End user auth response code-and-token's

[OAUTH-WG] End user auth response code-and-token's scope parameter

2010-07-02 Thread Andrew Arnott
> If the response type is code-and-token, the authorization server adds the > codeand state parameters to the redirection URI query component and the > access_token, scope, and expires_in to the redirection URI fragment using > theapplication/x-www-form-urlencoded format as defined by... Since th