[OAUTH-WG] review draft-ietf-oauth-security-topics-13 [2/3]

2019-11-11 Thread Hans Zandbelt
Hi, Please find my feedback on page 11-20 below. Hans. P14 4.2.4 For an RP there should be more explicit text and guidance about having a single dedicated immutatable redirect URI per client that "demultiplexes" access to the protected resource by storing the original location that the user agen

[OAUTH-WG] Tx Auth BOF agenda

2019-11-11 Thread Dick Hardt
Hello Everyone, see agenda below: Monday Nov-18-2019 1330 TxAuth Bof Agenda Introduction and Context Chairs 10 min Limitations and Feature Requests Limitations of OAuth Justin 10 min Limitations of OAuth Torsten 5 min Feature Requests Torsten 5 min Feature Requests

[OAUTH-WG] OAuth WG Agenda

2019-11-11 Thread Rifaat Shekh-Yusef
All, We did not receive any comments about the draft agenda. Here is the agenda for next week: https://datatracker.ietf.org/doc/agenda-106-oauth/ *Wednesday’s Agenda* Chairs Update (15 min) Security Topics – Torsten (15 min) Browser-based Apps – Aaron (30 min) TXAuth update – Dick/Justin (15 m

Re: [OAUTH-WG] OAuth WG Agenda

2019-11-11 Thread Brian Campbell
With a relatively short 15 minutes and the last time slot of the Wednesday meeting, I'm a little worried that the DPoP presentation and discussion will get rushed or truncated due to time constraints and/or overrun. Can I make a preemptive request for use of that buffer time on Thursday at the top

Re: [OAUTH-WG] OAuth WG Agenda

2019-11-11 Thread Rifaat Shekh-Yusef
Sure. It's yours. Regards, Rifaat On Mon, Nov 11, 2019 at 5:37 PM Brian Campbell wrote: > With a relatively short 15 minutes and the last time slot of the Wednesday > meeting, I'm a little worried that the DPoP presentation and discussion > will get rushed or truncated due to time constraints

Re: [OAUTH-WG] OAuth WG Agenda

2019-11-11 Thread Rifaat Shekh-Yusef
Here is the updated agenda: Wednesday’s Agenda Chairs Update (15 min) Security Topics – Torsten (15 min) Browser-based Apps – Aaron (30 min) TXAuth update – Dick/Justin (15 min) DPoP – Brian (15 min) Thursday’s Agenda DPoP - Brian (10 min) Rich Authorization – Torsten (20 min) Pushed Aut