M
To: Eran Hammer-Lahav
Cc: OAuth WG (oauth@ietf.org)
Subject: Re: [OAUTH-WG] End user auth response code-and-token's scope parameter
Ah! Yes I'd missed the second scope parameter that web servers have the
opportunity to see. And your point makes sense.
Is this reduced scope on the a
m:* oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] *On Behalf
> Of *Andrew Arnott
> *Sent:* Friday, July 02, 2010 9:26 AM
> *To:* OAuth WG (oauth@ietf.org)
> *Subject:* [OAUTH-WG] End user auth response code-and-token's scope
> parameter
>
>
>
>
>
>
client when using
the authorization code and provide greater access.
EHL
From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of
Andrew Arnott
Sent: Friday, July 02, 2010 9:26 AM
To: OAuth WG (oauth@ietf.org)
Subject: [OAUTH-WG] End user auth response code-and-token's
> If the response type is code-and-token, the authorization server adds the
> codeand state parameters to the redirection URI query component and the
> access_token, scope, and expires_in to the redirection URI fragment using
> theapplication/x-www-form-urlencoded format as defined by...
Since th