Return-Path: <janakama360@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 7F31F12003E
 for <oauth@ietfa.amsl.com>; Sun, 22 Sep 2019 00:45:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.747
X-Spam-Level: 
X-Spam-Status: No, score=-1.747 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25,
 FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001,
 SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001]
 autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id y0YIp_UyixrS for <oauth@ietfa.amsl.com>;
 Sun, 22 Sep 2019 00:45:55 -0700 (PDT)
Received: from mail-wm1-x329.google.com (mail-wm1-x329.google.com
 [IPv6:2a00:1450:4864:20::329])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 9C0E712002F
 for <oauth@ietf.org>; Sun, 22 Sep 2019 00:45:54 -0700 (PDT)
Received: by mail-wm1-x329.google.com with SMTP id y135so12587105wmc.1
 for <oauth@ietf.org>; Sun, 22 Sep 2019 00:45:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; 
 h=mime-version:references:in-reply-to:from:date:message-id:subject:to
 :cc; bh=GblSD8+BT1lXwo5vJlcXxBd/VKDixyROnGvtMKdd7nE=;
 b=m268xB2JyiCc/qnhqEgQNs1fnCZe1krrNQtMN9xR+DR+npYGVgbUYJe3HPlChSyAPG
 Y9dX1hXCcieome23zRMjKyfSGOrulhtLZ9gZ47BbpkGi5TkvYzdyj3laAcU2V6gNZ9UU
 KX7vuHTeWVfj0+QtD6MBsnHZAWzJ9T1SIMpU5u/yuhbJ1efEbPvv/F5YIgV3JwdwxCq4
 u2PXRWULhOhgNOVhvDRReYb14QYF8/c0cR4T6oMnHzSBlVwuDt4vQ5CSxbATMCE7LXjf
 D5bpu7JMY81hFx8mRi5nGFibF2vwesimhq8U0K+7zM6ZAFLjJvLMHSJhkZNWpN1XCj9m
 8Qag==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:mime-version:references:in-reply-to:from:date
 :message-id:subject:to:cc;
 bh=GblSD8+BT1lXwo5vJlcXxBd/VKDixyROnGvtMKdd7nE=;
 b=iSaSzJbWyAQN/lW5ujyuLrvidGSh8nXRwU5cra5u5RKcESrwFurjzKnQIPOmMW3fCx
 GeGRZ8PQska5/xL26m+rZdKS42RAnAwo64rLwYkksBCqU/9/Oo0XY/FGZEVkwOdYHS8M
 mhxZ2I5v7JAh+AD6dwiPc4JelJu4d7qmctnnRnRZDb6ydHhyBXAIs6xI7QK41gtaxEQI
 5J+65MQ2TxhLn188ZZaTwO0G/muLBBiq6HUeQ5JLjpHeiLV0NbHec+j+sCZOL2HzHvLE
 0eVoGPV06lpS3WvSrNFhyEJQp6xbF99CIj4H53Olr7oWEUQBVKBV/xwStBHZI86X6P+O
 whPw==
X-Gm-Message-State: APjAAAUv7rwVN/uUw949d/K7fT4zcy2P9m+auyyQq/BXytdEw4/0+bEG
 gcy3ylRJvJdqxOZiY7rhbjSiyGlVT11TLWY8ctO8W0Be
X-Google-Smtp-Source: APXvYqyfxJNM5SVGRqXtcS+wnUDur0wBHZz2GP4nm8DoerxBmblLm8a4bWbWzfMVnQH/NFE8PYcjiEnlFg/ZiwcGWTg=
X-Received: by 2002:a05:600c:24d1:: with SMTP id
 17mr9457645wmu.104.1569138353088; 
 Sun, 22 Sep 2019 00:45:53 -0700 (PDT)
MIME-Version: 1.0
References: <156907504831.22964.1710780113673136607.idtracker@ietfa.amsl.com>
 <A82AA337-86BF-485D-901B-3A3C73C6177B@lodderstedt.net>
In-Reply-To: <A82AA337-86BF-485D-901B-3A3C73C6177B@lodderstedt.net>
From: Janak Amarasena <janakama360@gmail.com>
Date: Sun, 22 Sep 2019 13:15:44 +0530
Message-ID: <CAM7dPt1vUQhFd0uMMS7e=WvzkiRP9UAuEcO7uGANTz-4qL58ug@mail.gmail.com>
To: Torsten Lodderstedt <torsten@lodderstedt.net>
Cc: oauth <oauth@ietf.org>, Justin Richer <justin@bspk.io>
Content-Type: multipart/alternative; boundary="00000000000023ae8a05931f7ee9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/2ngyvVV7dJO6OtglcMSf7qXCqxI>
Subject: Re: [OAUTH-WG] Fwd: New Version Notification for
 draft-lodderstedt-oauth-rar-02.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 22 Sep 2019 07:45:56 -0000

--00000000000023ae8a05931f7ee9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

Since the "authorization_details" parameter is newly introduced I feel it
would be better to show how this is used with the existing authorization
request at the beginning of the specification. Maybe a small sample of the
complete authorization request in the "introduction" section.

Also, in the "Security Considerations" section it says

Authorization details are sent through the user agent in case of an

OAuth authorization request, which makes them vulnerable to

modifications by the *user*.


Do we really need to worry that the "authorization_details" could be
manipulated by the user(Resource Owner) as the client is trying to access
the users' resources which the user is giving consent to? Also, the
resulting token will contain the given permissions as well.

Best Regards,
Janak Amarasena

On Sat, Sep 21, 2019 at 11:21 PM Torsten Lodderstedt <
torsten@lodderstedt.net> wrote:

> Hi all,
>
> I just published a draft about =E2=80=9COAuth 2.0 Rich Authorization Requ=
ests=E2=80=9D
> (formerly known as =E2=80=9Cstructured scopes=E2=80=9D).
>
> https://tools.ietf.org/html/draft-lodderstedt-oauth-rar-02
>
> It specifies a new parameter =E2=80=9Cauthorization_details" that is used=
 to carry
> fine grained authorization data in the OAuth authorization request. This
> mechanisms was designed based on experiences gathered in the field of ope=
n
> banking, e.g. PSD2, and is intended to make the implementation of rich an=
d
> transaction oriented authorization requests much easier than with current
> OAuth 2.0.
>
> I=E2=80=99m happy that Justin Richer and Brian Campbell joined me as auth=
ors of
> this draft. We would would like to thank Daniel Fett, Sebastian Ebling,
> Dave Tonge, Mike Jones, Nat Sakimura, and Rob Otto for their valuable
> feedback during the preparation of this draft.
>
> We look forward to getting your feedback.
>
> kind regards,
> Torsten.
>
> Begin forwarded message:
>
> *From: *internet-drafts@ietf.org
> *Subject: **New Version Notification for
> draft-lodderstedt-oauth-rar-02.txt*
> *Date: *21. September 2019 at 16:10:48 CEST
> *To: *"Justin Richer" <ietf@justin.richer.org>, "Torsten Lodderstedt" <
> torsten@lodderstedt.net>, "Brian Campbell" <bcampbell@pingidentity.com>
>
>
> A new version of I-D, draft-lodderstedt-oauth-rar-02.txt
> has been successfully submitted by Torsten Lodderstedt and posted to the
> IETF repository.
>
> Name: draft-lodderstedt-oauth-rar
> Revision: 02
> Title: OAuth 2.0 Rich Authorization Requests
> Document date: 2019-09-20
> Group: Individual Submission
> Pages: 16
> URL:
> https://www.ietf.org/internet-drafts/draft-lodderstedt-oauth-rar-02.txt
> Status:
> https://datatracker.ietf.org/doc/draft-lodderstedt-oauth-rar/
> Htmlized:       https://tools.ietf.org/html/draft-lodderstedt-oauth-rar-0=
2
> Htmlized:
> https://datatracker.ietf.org/doc/html/draft-lodderstedt-oauth-rar
> Diff:
> https://www.ietf.org/rfcdiff?url2=3Ddraft-lodderstedt-oauth-rar-02
>
> Abstract:
>   This document specifies a new parameter "authorization_details" that
>   is used to carry fine grained authorization data in the OAuth
>   authorization request.
>
>
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> The IETF Secretariat
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>

--00000000000023ae8a05931f7ee9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>Since the=C2=A0<span style=3D"color=
:rgb(0,0,0);font-size:13.3333px">&quot;authorization_details&quot; paramete=
r is newly introduced I feel it would be better to show how this is used wi=
th the existing authorization request at the beginning=C2=A0of the specific=
ation. Maybe a small sample of the complete authorization request in the &q=
uot;introduction&quot; section.</span></div><div><span style=3D"color:rgb(0=
,0,0);font-size:13.3333px"><br></span></div><div><span style=3D"color:rgb(0=
,0,0);font-size:13.3333px">Also, in the &quot;Security Considerations&quot;=
 section it says=C2=A0</span></div><blockquote style=3D"margin:0 0 0 40px;b=
order:none;padding:0px"><div><pre class=3D"gmail-newpage" style=3D"font-siz=
e:13.3333px;margin-top:0px;margin-bottom:0px;break-before:page;color:rgb(0,=
0,0)">Authorization details are sent through the user agent in case of an</=
pre></div></blockquote><blockquote style=3D"margin:0 0 0 40px;border:none;p=
adding:0px"><div><pre class=3D"gmail-newpage" style=3D"font-size:13.3333px;=
margin-top:0px;margin-bottom:0px;break-before:page;color:rgb(0,0,0)">OAuth =
authorization request, which makes them vulnerable to</pre></div><div><pre =
class=3D"gmail-newpage" style=3D"font-size:13.3333px;margin-top:0px;margin-=
bottom:0px;break-before:page;color:rgb(0,0,0)">modifications by the <b>user=
</b>.</pre><pre class=3D"gmail-newpage" style=3D"font-size:13.3333px;margin=
-top:0px;margin-bottom:0px;break-before:page;color:rgb(0,0,0)"><br></pre></=
div></blockquote>Do we really need to worry that the &quot;authorization_de=
tails&quot; could be manipulated=C2=A0by the user(Resource Owner) as the cl=
ient is trying to access the users&#39; resources which the user is giving=
=C2=A0consent to? Also, the resulting token will contain the given permissi=
ons as well.=C2=A0<font color=3D"#000000" face=3D"monospace"><span style=3D=
"font-size:13.3333px;white-space:pre"><br></span></font><div><br></div><div=
>Best Regards,</div><div>Janak Amarasena</div></div><br><div class=3D"gmail=
_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Sat, Sep 21, 2019 at 11:21=
 PM Torsten Lodderstedt &lt;<a href=3D"mailto:torsten@lodderstedt.net">tors=
ten@lodderstedt.net</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex"><div style=3D"overflow-wrap: break-word;">Hi all,=C2=A0<=
div><br></div><div>I just published a draft about =E2=80=9COAuth 2.0 Rich A=
uthorization Requests=E2=80=9D (formerly known as =E2=80=9Cstructured scope=
s=E2=80=9D).=C2=A0</div><div><br></div><div><a href=3D"https://tools.ietf.o=
rg/html/draft-lodderstedt-oauth-rar-02" target=3D"_blank">https://tools.iet=
f.org/html/draft-lodderstedt-oauth-rar-02</a></div><div><br></div><div>It s=
pecifies a new parameter=C2=A0=E2=80=9Cauthorization_details&quot;=C2=A0tha=
t is used to carry fine grained authorization data in the OAuth authorizati=
on request. This mechanisms was designed based on experiences gathered in t=
he field of open banking, e.g. PSD2, and is intended to make the implementa=
tion of rich and transaction oriented authorization requests much easier th=
an with current OAuth 2.0.</div><div><br></div><div>I=E2=80=99m happy that =
Justin Richer and Brian Campbell joined me as authors of this draft. We wou=
ld would like to thank Daniel Fett, Sebastian Ebling, Dave Tonge, Mike Jone=
s, Nat Sakimura, and Rob Otto for their valuable feedback during the prepar=
ation of this draft.</div><div><br></div><div>We look forward to getting yo=
ur feedback.=C2=A0</div><div><br></div><div>kind regards,</div><div>Torsten=
.=C2=A0<br><div><br><blockquote type=3D"cite"><div>Begin forwarded message:=
</div><br class=3D"gmail-m_1158921302350827193Apple-interchange-newline"><d=
iv style=3D"margin:0px"><span style=3D"font-family:-webkit-system-font,&quo=
t;Helvetica Neue&quot;,Helvetica,sans-serif;color:rgb(0,0,0)"><b>From: </b>=
</span><span style=3D"font-family:-webkit-system-font,&quot;Helvetica Neue&=
quot;,Helvetica,sans-serif"><a href=3D"mailto:internet-drafts@ietf.org" tar=
get=3D"_blank">internet-drafts@ietf.org</a><br></span></div><div style=3D"m=
argin:0px"><span style=3D"font-family:-webkit-system-font,&quot;Helvetica N=
eue&quot;,Helvetica,sans-serif;color:rgb(0,0,0)"><b>Subject: </b></span><sp=
an style=3D"font-family:-webkit-system-font,&quot;Helvetica Neue&quot;,Helv=
etica,sans-serif"><b>New Version Notification for draft-lodderstedt-oauth-r=
ar-02.txt</b><br></span></div><div style=3D"margin:0px"><span style=3D"font=
-family:-webkit-system-font,&quot;Helvetica Neue&quot;,Helvetica,sans-serif=
;color:rgb(0,0,0)"><b>Date: </b></span><span style=3D"font-family:-webkit-s=
ystem-font,&quot;Helvetica Neue&quot;,Helvetica,sans-serif">21. September 2=
019 at 16:10:48 CEST<br></span></div><div style=3D"margin:0px"><span style=
=3D"font-family:-webkit-system-font,&quot;Helvetica Neue&quot;,Helvetica,sa=
ns-serif;color:rgb(0,0,0)"><b>To: </b></span><span style=3D"font-family:-we=
bkit-system-font,&quot;Helvetica Neue&quot;,Helvetica,sans-serif">&quot;Jus=
tin Richer&quot; &lt;<a href=3D"mailto:ietf@justin.richer.org" target=3D"_b=
lank">ietf@justin.richer.org</a>&gt;, &quot;Torsten Lodderstedt&quot; &lt;<=
a href=3D"mailto:torsten@lodderstedt.net" target=3D"_blank">torsten@lodders=
tedt.net</a>&gt;, &quot;Brian Campbell&quot; &lt;<a href=3D"mailto:bcampbel=
l@pingidentity.com" target=3D"_blank">bcampbell@pingidentity.com</a>&gt;<br=
></span></div><br><div><div><br>A new version of I-D, draft-lodderstedt-oau=
th-rar-02.txt<br>has been successfully submitted by Torsten Lodderstedt and=
 posted to the<br>IETF repository.<br><br>Name:<span class=3D"gmail-m_11589=
21302350827193Apple-tab-span" style=3D"white-space:pre-wrap">	</span><span =
class=3D"gmail-m_1158921302350827193Apple-tab-span" style=3D"white-space:pr=
e-wrap">	</span>draft-lodderstedt-oauth-rar<br>Revision:<span class=3D"gmai=
l-m_1158921302350827193Apple-tab-span" style=3D"white-space:pre-wrap">	</sp=
an>02<br>Title:<span class=3D"gmail-m_1158921302350827193Apple-tab-span" st=
yle=3D"white-space:pre-wrap">	</span><span class=3D"gmail-m_115892130235082=
7193Apple-tab-span" style=3D"white-space:pre-wrap">	</span>OAuth 2.0 Rich A=
uthorization Requests<br>Document date:<span class=3D"gmail-m_1158921302350=
827193Apple-tab-span" style=3D"white-space:pre-wrap">	</span>2019-09-20<br>=
Group:<span class=3D"gmail-m_1158921302350827193Apple-tab-span" style=3D"wh=
ite-space:pre-wrap">	</span><span class=3D"gmail-m_1158921302350827193Apple=
-tab-span" style=3D"white-space:pre-wrap">	</span>Individual Submission<br>=
Pages:<span class=3D"gmail-m_1158921302350827193Apple-tab-span" style=3D"wh=
ite-space:pre-wrap">	</span><span class=3D"gmail-m_1158921302350827193Apple=
-tab-span" style=3D"white-space:pre-wrap">	</span>16<br>URL: =C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<a href=3D"https://ww=
w.ietf.org/internet-drafts/draft-lodderstedt-oauth-rar-02.txt" target=3D"_b=
lank">https://www.ietf.org/internet-drafts/draft-lodderstedt-oauth-rar-02.t=
xt</a><br>Status: =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<a href=
=3D"https://datatracker.ietf.org/doc/draft-lodderstedt-oauth-rar/" target=
=3D"_blank">https://datatracker.ietf.org/doc/draft-lodderstedt-oauth-rar/</=
a><br>Htmlized: =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<a href=3D"https://tool=
s.ietf.org/html/draft-lodderstedt-oauth-rar-02" target=3D"_blank">https://t=
ools.ietf.org/html/draft-lodderstedt-oauth-rar-02</a><br>Htmlized: =C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<a href=3D"https://datatracker.ietf.org/doc/h=
tml/draft-lodderstedt-oauth-rar" target=3D"_blank">https://datatracker.ietf=
.org/doc/html/draft-lodderstedt-oauth-rar</a><br>Diff: =C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<a href=3D"https://www.ietf.org/r=
fcdiff?url2=3Ddraft-lodderstedt-oauth-rar-02" target=3D"_blank">https://www=
.ietf.org/rfcdiff?url2=3Ddraft-lodderstedt-oauth-rar-02</a><br><br>Abstract=
:<br> =C2=A0=C2=A0This document specifies a new parameter &quot;authorizati=
on_details&quot; that<br> =C2=A0=C2=A0is used to carry fine grained authori=
zation data in the OAuth<br> =C2=A0=C2=A0authorization request.<br><br><br>=
<br><br>Please note that it may take a couple of minutes from the time of s=
ubmission<br>until the htmlized version and diff are available at <a href=
=3D"http://tools.ietf.org" target=3D"_blank">tools.ietf.org</a>.<br><br>The=
 IETF Secretariat<br><br></div></div></blockquote></div><br></div></div>___=
____________________________________________<br>
OAuth mailing list<br>
<a href=3D"mailto:OAuth@ietf.org" target=3D"_blank">OAuth@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/oauth" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/listinfo/oauth</a><br>
</blockquote></div>

--00000000000023ae8a05931f7ee9--

