Re: [OAUTH-WG] One more comment on draft-ietf-oauth-v2-13

2011-03-25 Thread Eran Hammer-Lahav
> -Original Message- > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf > Of Lu, Hui-Lan (Huilan) > Sent: Thursday, March 17, 2011 2:31 PM > The required binding of the client and refresh token is implied. For clarity, > I > would suggest to make it explcit with t

[OAUTH-WG] One more comment on draft-ietf-oauth-v2-13

2011-03-17 Thread Lu, Hui-Lan (Huilan)
The required binding of the client and refresh token is implied. For clarity, I would suggest to make it explcit with the following edits: + In section 1.5, after the first sentence, add "Unlike the access token, the refresh token is bound to the client and is consumed only by the authorization