[OAUTH-WG] OAuth 2.0 Discovery Location

2016-02-21 Thread Samuel Erdtman
Hi, Here coms some review comments, In general I think this is a good document. //Samuel 2. Authorization Server Metadata token_endpoint, I would prefer if the requiredness of this parameter was put in the beginning instead of the end as with the other parameters. jwks_uri, I would like to c

Re: [OAUTH-WG] OAuth 2.0 Discovery Location

2016-02-21 Thread Samuel Erdtman
Hi, I agree that the user of “/.well-known/openid-configuration” is confusing and that it would be preferable with something else, but it is written as an example not necessarily a default. However to use “/.well-known/oauth-authorization-server” might be problematic if as written different appli