Re: [OAUTH-WG] Call for Adoption: OAuth 2.0 for Browser-Based Apps

"Richard Backman, Annabelle" <richanna@amazon.com> Wed, 19 December 2018 01:21 UTC

Return-Path: <prvs=8841463a1=richanna@amazon.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9FCDF130DE8 for <oauth@ietfa.amsl.com>; Tue, 18 Dec 2018 17:21:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.566
X-Spam-Level:
X-Spam-Status: No, score=-14.566 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.065, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=amazon.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rBDQG8ca5Bzh for <oauth@ietfa.amsl.com>; Tue, 18 Dec 2018 17:20:58 -0800 (PST)
Received: from smtp-fw-9101.amazon.com (smtp-fw-9101.amazon.com [207.171.184.25]) (using TLSv1.2 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 341751276D0 for <oauth@ietf.org>; Tue, 18 Dec 2018 17:20:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazon201209; t=1545182458; x=1576718458; h=from:to:subject:date:message-id:content-id: content-transfer-encoding:mime-version; bh=IwkhY6dwg27mdjazwJh+GiOWSa0gVrEUzblhtuVK9Vs=; b=jKZBqocliOinmEtT3xvA3blwMDgcpVRufCbM+vUuIwzHwJmUHrvdsOkv PIC6uOK3lpoaBvwIIExrpQ0gOVDHUebifpQcLPnvr7HA41Khw31O87MQf Rt6kpTzZFy31JXi+RTwvUCJh7J/NBzYt3TjYx30bEl16hFnvBTSfTCnna k=;
X-IronPort-AV: E=Sophos;i="5.56,253,1539648000"; d="scan'208";a="777024313"
Received: from sea3-co-svc-lb6-vlan3.sea.amazon.com (HELO email-inbound-relay-1a-807d4a99.us-east-1.amazon.com) ([10.47.22.38]) by smtp-border-fw-out-9101.sea19.amazon.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 19 Dec 2018 01:20:55 +0000
Received: from EX13MTAUWC001.ant.amazon.com (iad55-ws-svc-p15-lb9-vlan3.iad.amazon.com [10.40.159.166]) by email-inbound-relay-1a-807d4a99.us-east-1.amazon.com (8.14.7/8.14.7) with ESMTP id wBJ1Kpqu063633 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 19 Dec 2018 01:20:53 GMT
Received: from EX13D11UWC002.ant.amazon.com (10.43.162.174) by EX13MTAUWC001.ant.amazon.com (10.43.162.135) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Wed, 19 Dec 2018 01:20:53 +0000
Received: from EX13D11UWC004.ant.amazon.com (10.43.162.101) by EX13D11UWC002.ant.amazon.com (10.43.162.174) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Wed, 19 Dec 2018 01:20:52 +0000
Received: from EX13D11UWC004.ant.amazon.com ([10.43.162.101]) by EX13D11UWC004.ant.amazon.com ([10.43.162.101]) with mapi id 15.00.1367.000; Wed, 19 Dec 2018 01:20:52 +0000
From: "Richard Backman, Annabelle" <richanna@amazon.com>
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>, oauth <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] Call for Adoption: OAuth 2.0 for Browser-Based Apps
Thread-Index: AQHUlzkV+Cli+sUWS9WAastnHMBWKw==
Date: Wed, 19 Dec 2018 01:20:52 +0000
Message-ID: <691FAEB9-51F7-4967-9F55-9479CA21C7B1@amazon.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.10.0.180812
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.43.160.82]
Content-Type: text/plain; charset="utf-8"
Content-ID: <B8FBB822B0D9F148BD76ED2393527FB8@amazon.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/5n7Gz55fI-c7BOZGvrmum302LeE>
Subject: Re: [OAUTH-WG] Call for Adoption: OAuth 2.0 for Browser-Based Apps
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Dec 2018 01:21:02 -0000

I am in favor of adopting this as a working group document. There is a clear need for updated guidance for these clients.

-- 
Annabelle Richard Backman
AWS Identity
 

On 12/17/18, 1:02 PM, "OAuth on behalf of Hannes Tschofenig" <oauth-bounces@ietf.org on behalf of Hannes.Tschofenig@arm.com> wrote:

    Hi all,
    
    We would like to get a confirmation on the mailing list for the adoption of https://tools.ietf.org/html/draft-parecki-oauth-browser-based-apps-02 as a starting point for a BCP document about *OAuth 2.0 for Browser-Based Apps*.
    
    Please, let us know if you support or object to the adoption of this document by Jan. 7th 2019.
    
    Ciao
    Hannes & Rifaat
    IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
    
    _______________________________________________
    OAuth mailing list
    OAuth@ietf.org
    https://www.ietf.org/mailman/listinfo/oauth