Re: [OAUTH-WG] draft 16 notes on security considerations

2011-05-29 Thread Torsten Lodderstedt
Am 28.05.2011 20:25, schrieb Doug Tangren: I just re-read draft 16 on this memorial day weekend :) 1. I had a comment on the suggested use of the authorization code flow for native clients [1]. Section 10.9 on auth code transmission [2] suggests users of the auth code flow should implement

[OAUTH-WG] draft 16 notes on security considerations

2011-05-28 Thread Doug Tangren
I just re-read draft 16 on this memorial day weekend :) 1. I had a comment on the suggested use of the authorization code flow for native clients [1]. Section 10.9 on auth code transmission [2] suggests users of the auth code flow should implement tls on it's redirect uri. This makes sense for we