On 01/03/16 00:34, Brian Campbell wrote:
> +1 for "OAuth 2.0 Authorization Server Discovery” from those two options.
>
> But what about "OAuth 2.0 Authorization Server Metadata”?
>
> The document in its current scope (which I agree with, BTW) isn't really
> about discovery so much as about descri
Hi John,
On 28/02/16 01:15, John Bradley wrote:
> If the malicious client is registering it’s own redirect URI then option A
> won’t help.
>
> On the other hand the Good AS should identify the malicious client to the
> user.
How could that be done in practice, especially with an AS that provid
On Mon, Feb 29, 2016 at 11:35 PM Brian Campbell
wrote:
> +1 for "OAuth 2.0 Authorization Server Discovery” from those two options.
>
> But what about "OAuth 2.0 Authorization Server Metadata”?
>
> The document in its current scope (which I agree with, BTW) isn't really
> about discovery so much a
Inline
> On Mar 1, 2016, at 5:51 AM, Vladimir Dzhuvinov
> wrote:
>
> Hi John,
>
> On 28/02/16 01:15, John Bradley wrote:
>> If the malicious client is registering it’s own redirect URI then option A
>> won’t help.
>>
>> On the other hand the Good AS should identify the malicious client to t
Inline >
On 01/03/16 16:33, John Bradley wrote:
> Inline
>
>> On Mar 1, 2016, at 5:51 AM, Vladimir Dzhuvinov
>> wrote:
>>
>> Hi John,
>>
>> On 28/02/16 01:15, John Bradley wrote:
>>> If the malicious client is registering it’s own redirect URI then option A
>>> won’t help.
>>>
>>> On the other
I'm fine with this clarification as it is more correctly describes the
purpose of the document.
Thanks,
George
On 2/29/16 5:34 PM, Brian Campbell wrote:
+1 for "OAuth 2.0 Authorization Server Discovery” from those two options.
But what about "OAuth 2.0 Authorization Server Metadata”?
The doc
+1, this was a driving requirement when I wrote the first strawman. I can’t
tell you the number of times I had frameworks mess things up with OAuth 1,
which does exactly the algorithm that you mention below.
I’m currently in favor of just leaving the repeated parameter and header out of
the co