[OAUTH-WG] Definition of resource owner versus end-user

"Alastair Mair" <AMair@mgtplc.com> Thu, 11 November 2010 12:21 UTC

Return-Path: <AMair@mgtplc.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 96D713A6A6E for <oauth@core3.amsl.com>; Thu, 11 Nov 2010 04:21:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.162
X-Spam-Level:
X-Spam-Status: No, score=-0.162 tagged_above=-999 required=5 tests=[BAYES_05=-1.11, SARE_UNSUB22=0.948]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6jj9NZ7bQb3K for <oauth@core3.amsl.com>; Thu, 11 Nov 2010 04:21:48 -0800 (PST)
Received: from mta0.mgtplc.com (mta0.mgtplc.com [80.195.74.37]) by core3.amsl.com (Postfix) with ESMTP id 319F23A6A3F for <oauth@ietf.org>; Thu, 11 Nov 2010 04:21:48 -0800 (PST)
Received: from cetus.iona.mgtlimited.com (cetus.iona.mgtlimited.com [192.168.102.77]) by mta0.mgtplc.com (8.13.8+Sun/8.13.8) with ESMTP id oABCM552014630 for <oauth@ietf.org>; Thu, 11 Nov 2010 12:22:05 GMT
Received: from mgt_dom-MTA by cetus.iona.mgtlimited.com with Novell_GroupWise; Thu, 11 Nov 2010 12:22:05 +0000
Message-Id: <4CDBDFEC020000500002793C@cetus.iona.mgtlimited.com>
X-Mailer: Novell GroupWise Internet Agent 8.0.0
Date: Thu, 11 Nov 2010 12:22:04 +0000
From: Alastair Mair <AMair@mgtplc.com>
To: oauth@ietf.org
Mime-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
X-MGt-MailScanner-Information: Please contact the ISP for more information
X-MGt-MailScanner-ID: oABCM552014630
X-MGt-MailScanner: Found to be clean
X-MGt-MailScanner-From: amair@mgtplc.com
Subject: [OAUTH-WG] Definition of resource owner versus end-user
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Nov 2010 12:23:15 -0000

In the current draft spec section 1.2 on terminology the definition of resource owner is "An entity capable of granting access to a protected resource" and end user is "A human resource owner"

In section 4.1.2 "Resource owner Password credentials" it talks of supplying the resource owner's username and password. However the text below talks of the server validating the end-user credentials which is slightly confusing.

I note that the initial draft (draft 1) defined resource owner as "an entity (generally an end-user)..." So, is the intention that resource owner and end-user are effectively synonymous?

-- 



Please consider the environment before printing this email

*********************************************************************
This e-mail and any attachments are confidential.  If it is not for you, please inform us and delete it immediately without disclosing, copying, or distributing it.

If the content is not about the business of the MGt Group or its clients, then it is neither from nor sanctioned by the MGt Group.  Use of this or any other MGt Group e-mail facility signifies consent to interception by the MGt Group. The views expressed in this email or any attachments may not reflect the views and opinions of the MGt Group.

This message has been scanned for viruses and dangerous content by MailScanner, but the MGt Group accepts no liability for any damage caused by the transmission of any viruses.

MGt plc is a public limited company registered in Scotland (SC175703) with its registered office at Cluny Court, John Smith Business Park, Kirkcaldy, Fife, KY2 6QJ.

**********************************************************************

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.