Discussion:
[OAUTH-WG] Working Group Last Call on "OAuth 2.0 for Native Apps"
Hannes Tschofenig
2016-07-21 08:05:42 UTC
Permalink
Hi all,

William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.

The document can be found here:
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03

Please have your comments in no later than August 8th.

Ciao
Hannes & Derek
Torsten Lodderstedt
2016-07-24 17:30:33 UTC
Permalink
Hi,

generally, I considers this a highly valuable contribution and support
to move it forward.

Some nits:

section 7.3, last paragraph: "... as it is less susceptible
to misconfigured routing and client side firewalls Note ..." - I
think a period is missing between "firewalls" and "Note" potentially a
line break would be appropriate.

section 8.2 - The term PKCE is used in the second paragraph but not
defined before the fourth paragraph. I suggest to define PKCE on first use.

best regards,
Torsten.
Post by Hannes Tschofenig
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
Brian Campbell
2016-07-27 21:48:29 UTC
Permalink
I likewise believe there is a lot of value in this work and support the
document moving forward.

I reviewed -03 and have just a couple nits:

Loopback URI Redirection in section 3
<https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03#section-7.3>
(which the author is already aware of because he mentioned it to me)
doesn't fully account for how a path component of the URI would be used to
allow a client to use and rely on distinct per-AS redirect URIs.

Appendix A.1. iOS Implementation Details
<https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03#appendix-A.1>
has "Clients SHOULD use Universal Links for authorization requests ... "
but, in the context of what's being discussed there, shouldn't it say to
use Universal Links for *redirect URIs*? Or am I confused here?


On Sun, Jul 24, 2016 at 11:30 AM, Torsten Lodderstedt <
Hi,
generally, I considers this a highly valuable contribution and support to
move it forward.
section 7.3, last paragraph: "... as it is less susceptible
to misconfigured routing and client side firewalls Note ..." - I think
a period is missing between "firewalls" and "Note" potentially a line break
would be appropriate.
section 8.2 - The term PKCE is used in the second paragraph but not
defined before the fourth paragraph. I suggest to define PKCE on first use.
best regards,
Torsten.
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
The document can be found here:https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
Ulrich Herberg
2016-07-30 23:32:08 UTC
Permalink
Hannes,

I think this is a good document and support it. Still, I asked
questions that have never been responded to on this list:
https://www.ietf.org/mail-archive/web/oauth/current/msg16293.html

Is it possible to address my comments during the WGLC?

Best regards
Ulrich

On Thu, Jul 21, 2016 at 1:05 AM, Hannes Tschofenig
Post by Hannes Tschofenig
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
Dick Hardt
2016-08-03 15:53:14 UTC
Permalink
I reviewed the document and have no comments.

+1 to adoption

On Thu, Jul 21, 2016 at 1:05 AM, Hannes Tschofenig <
Post by Hannes Tschofenig
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
--
Subscribe to the HARDTWARE <http://hardtware.com/> mail list to learn about
projects I am working on!
Ulrich Herberg
2016-09-05 19:20:47 UTC
Permalink
Hannes,

any updates on this? WGLC has ended almost a month ago.

Regards
Ulrich
Post by Dick Hardt
I reviewed the document and have no comments.
+1 to adoption
On Thu, Jul 21, 2016 at 1:05 AM, Hannes Tschofenig
Post by Hannes Tschofenig
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
--
Subscribe to the HARDTWARE mail list to learn about projects I am working
on!
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
Ulrich Herberg
2016-09-08 02:39:03 UTC
Permalink
Thanks!

On Wed, Sep 7, 2016 at 6:04 AM, Hannes Tschofenig
Hi Ulrich,
I will be working with William on the shepherd write-up.
Ciao
Hannes
Post by Ulrich Herberg
Hannes,
any updates on this? WGLC has ended almost a month ago.
Regards
Ulrich
Post by Dick Hardt
I reviewed the document and have no comments.
+1 to adoption
On Thu, Jul 21, 2016 at 1:05 AM, Hannes Tschofenig
Post by Hannes Tschofenig
Hi all,
William has submitted an update, as promised during the OAuth WG session
on Monday. Hence, we will start a Last Call for comments on the "OAuth
2.0 for Native Apps" specification.
https://tools.ietf.org/html/draft-ietf-oauth-native-apps-03
Please have your comments in no later than August 8th.
Ciao
Hannes & Derek
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
--
Subscribe to the HARDTWARE mail list to learn about projects I am working
on!
_______________________________________________
OAuth mailing list
https://www.ietf.org/mailman/listinfo/oauth
Loading...