Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-06 Thread Jacob Ideskog
; function. Scopes have similar issues, but this structure adds more >> opportunities for mistakes just due to the possible increased complexity. >> > >> > -Justin >> > >> > From: OAuth [oauth-boun...@ietf.org] on beha

Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-06 Thread Torsten Lodderstedt
. > > > > -Justin > > ____________ > > From: OAuth [oauth-boun...@ietf.org <mailto:oauth-boun...@ietf.org>] on > > behalf of Jacob Ideskog [jacob.ides...@curity.io > > <mailto:jacob.ides...@curity.io>] > > Sent: Friday, S

Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-06 Thread Jacob Ideskog
t need that detail to > function. Scopes have similar issues, but this structure adds more > opportunities for mistakes just due to the possible increased complexity. > > > > -Justin > > ____ > > From: OAuth [oauth-boun...@ietf.org] o

Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-04 Thread Torsten Lodderstedt
Ideskog > [jacob.ides...@curity.io] > Sent: Friday, September 3, 2021 10:42 AM > To: oauth > Subject: [OAUTH-WG] RAR 05 - Token response with sensitive data in > draft-ietf-oauth-rar-05 > > Hi all, > > I have a question about section 7.0 and 7.1 in draft-ietf-oauth-rar-

Re: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-03 Thread Justin Richer
g] on behalf of Jacob Ideskog [jacob.ides...@curity.io] Sent: Friday, September 3, 2021 10:42 AM To: oauth Subject: [OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05 Hi all, I have a question about section 7.0 and 7.1 in draft-ietf-oauth-rar-05 that describes the

[OAUTH-WG] RAR 05 - Token response with sensitive data in draft-ietf-oauth-rar-05

2021-09-03 Thread Jacob Ideskog
Hi all, I have a question about section 7.0 and 7.1 in draft-ietf-oauth-rar-05 that describes the token response. The authorization_details values could be sensitive in their nature. The example in section 7.1 highlights this nicely. The accounts array is empty when the client requests it, but is