John Bradley
2016-03-20 21:17:53 UTC
We have had a number of discussions about splitting the audience part of PoP key distribution out into itâs own draft
Phil also requested a draft on how I propose propose that proper audiencing of access tokens can mitigate against the threat of bearer access token leakage.
In response Brian Campbell and I have created a short 00 draft on how the client can specify the resource that it is requesting a token for without overloading scopes.
I hope that this will make some of the issues clearer for our discussion.
As Justin pointed out we may also want to separate out offline access and some other common things from scope as well. This is intended to start the discussion not preclude other discussions around how to reduce the overloading of scope.
Regards
John Bradley
Phil also requested a draft on how I propose propose that proper audiencing of access tokens can mitigate against the threat of bearer access token leakage.
In response Brian Campbell and I have created a short 00 draft on how the client can specify the resource that it is requesting a token for without overloading scopes.
I hope that this will make some of the issues clearer for our discussion.
As Justin pointed out we may also want to separate out offline access and some other common things from scope as well. This is intended to start the discussion not preclude other discussions around how to reduce the overloading of scope.
Regards
John Bradley
Subject: New Version Notification for draft-campbell-oauth-resource-indicators-00.txt
Date: March 20, 2016 at 8:14:14 PM GMT
A new version of I-D, draft-campbell-oauth-resource-indicators-00.txt
has been successfully submitted by Brian Campbell and posted to the
IETF repository.
Name: draft-campbell-oauth-resource-indicators
Revision: 00
Title: Resource Indicators for OAuth 2.0
Document date: 2016-03-20
Group: Individual Submission
Pages: 7
URL: https://www.ietf.org/internet-drafts/draft-campbell-oauth-resource-indicators-00.txt
Status: https://datatracker.ietf.org/doc/draft-campbell-oauth-resource-indicators/
Htmlized: https://tools.ietf.org/html/draft-campbell-oauth-resource-indicators-00
This straw-man specification defines an extension to The OAuth 2.0
Authorization Framework that enables the client and authorization
server to more explicitly to communicate about the protected
resource(s) to be accessed.
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
The IETF Secretariat
Date: March 20, 2016 at 8:14:14 PM GMT
A new version of I-D, draft-campbell-oauth-resource-indicators-00.txt
has been successfully submitted by Brian Campbell and posted to the
IETF repository.
Name: draft-campbell-oauth-resource-indicators
Revision: 00
Title: Resource Indicators for OAuth 2.0
Document date: 2016-03-20
Group: Individual Submission
Pages: 7
URL: https://www.ietf.org/internet-drafts/draft-campbell-oauth-resource-indicators-00.txt
Status: https://datatracker.ietf.org/doc/draft-campbell-oauth-resource-indicators/
Htmlized: https://tools.ietf.org/html/draft-campbell-oauth-resource-indicators-00
This straw-man specification defines an extension to The OAuth 2.0
Authorization Framework that enables the client and authorization
server to more explicitly to communicate about the protected
resource(s) to be accessed.
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
The IETF Secretariat