Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-08-29 Thread Torsten Lodderstedt
> On 11. Aug 2020, at 23:55, Brian Campbell > wrote: > > Hi Francis, > > My apologies for the tardy response to this - I was away for some time on > holiday. But thank you for the review and feedback on the draft. I've tried > to respond inline below. > > > On Fri, Jul 31, 2020 at 5:01 P

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-08-12 Thread Francis Pouatcha
On Wed, Aug 12, 2020 at 1:03 PM Brian Campbell wrote: > I'm honestly having a hard time following what you are asking for. But > there is already the following text in sec 1 that mentions non-repudiation > via JWT-based request objects and by implication the basic request method > does not provid

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-08-12 Thread Brian Campbell
I'm honestly having a hard time following what you are asking for. But there is already the following text in sec 1 that mentions non-repudiation via JWT-based request objects and by implication the basic request method does not provide non-repudiation. The pushed authorization request endpoint

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-08-11 Thread Francis Pouatcha
Hello Brian, On Tue, Aug 11, 2020 at 5:55 PM Brian Campbell wrote: > Hi Francis, > > My apologies for the tardy response to this - I was away for some time on > holiday. But thank you for the review and feedback on the draft. I've tried > to respond inline below. > > > On Fri, Jul 31, 2020 at 5:

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-08-11 Thread Brian Campbell
Hi Francis, My apologies for the tardy response to this - I was away for some time on holiday. But thank you for the review and feedback on the draft. I've tried to respond inline below. On Fri, Jul 31, 2020 at 5:01 PM Francis Pouatcha wrote: > Bellow is the only remark I found from reviewing

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-07-31 Thread Francis Pouatcha
Bellow is the only remark I found from reviewing the draft draft: 2.1. Request: requires the parameters "code_challenge" and "code_challenge_method" but https://openid.net/specs/openid-financial-api-part-2-ID2.html#confidential-client mentions that RFC7636 is not required for confidential client

[OAUTH-WG] I-D Action: draft-ietf-oauth-par-03.txt

2020-07-31 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : OAuth 2.0 Pushed Authorization Requests Authors : Torsten Lodderstedt Br