[OAUTH-WG] Token Introspection: Misc Review Comments

2015-03-05 Thread Anthony Nadalin
Some comments: > The endpoint MAY allow other parameters to provide further context to the > query. If the endpoint does not understand these the endpoint must ignore. The only MUST in this specification is to return the "active" Boolean, but this is still underspecified as there is no definit

Re: [OAUTH-WG] Token Introspection: Misc Review Comments

2015-03-04 Thread Justin Richer
> On Mar 3, 2015, at 5:59 AM, Hannes Tschofenig > wrote: > > Hi Justin, Hi all, > > here are some random review comments: > > FROM: > > " Since > OAuth 2.0 [RFC6749] defines no direct relationship between the > authorization server and the protected resource, only that they must > ha

[OAUTH-WG] Token Introspection: Misc Review Comments

2015-03-03 Thread Hannes Tschofenig
Hi Justin, Hi all, here are some random review comments: FROM: " Since OAuth 2.0 [RFC6749] defines no direct relationship between the authorization server and the protected resource, only that they must have an agreement on the tokens themselves, there have been many different appr