Re: [OAUTH-WG] Call for adoption - OAuth 2.1 document
Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com> Wed, 15 July 2020 19:14 UTC
Return-Path: <rifaat.s.ietf@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2EFB03A0F97 for <oauth@ietfa.amsl.com>; Wed, 15 Jul 2020 12:14:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_IMAGE_RATIO_06=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zUQVhnthyZ2v for <oauth@ietfa.amsl.com>; Wed, 15 Jul 2020 12:14:12 -0700 (PDT)
Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C809A3A0F3E for <oauth@ietf.org>; Wed, 15 Jul 2020 12:14:09 -0700 (PDT)
Received: by mail-wr1-x435.google.com with SMTP id o11so3966588wrv.9 for <oauth@ietf.org>; Wed, 15 Jul 2020 12:14:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=bxFNJJ3DbskcjidVI/EbgmksaF5xZynNYLQjiUP3fSY=; b=clkIWtqvVwujhvwJZeiXgo8DNvOI5JAHByRscR+FxS7Z9pChmYa+sbFwYdsZ99Gs+H /BAvQ+Dma08Qc5Gs5AgQAMSmHRkfSSymBrxCjfHXa0pJkCcgX9p2aY3IH8JBSqJyGY94 Hob6Vk5wJ9WWVKv4gzCUsC6AsUND+HnofAz9fhuQHDbjM2v13fa7uuTh8h0nPb5oyIOe 8AX/6Ctvqz7FK0/FqMAdNQWvR0XLvqsy0ao4ZeUuh9d/94cktU6fOnXg8I1t83Le5Ier sOnRg/kPhXMzTURf1jVg0PFLNG+EYvmcmPHs3Idmt0ApkZmr3XM+n4+Hbgm6vIYfQqyf 7EJQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=bxFNJJ3DbskcjidVI/EbgmksaF5xZynNYLQjiUP3fSY=; b=deac/3CvnoP5qRm3sBMM0iAkedL3AUowEjR7eHKRULkKJIAHwew6SNbjnH4jTPpe2U 3HLPdfm04HL0KSyp8cL3OoLhKx4MJCHAhdKYzuan7zlnIwcqRjKrUfZ/WwdF5T22Dook wQJgU3tWiwfUuXOMYs+TBsXd/XG2tEl/h2+uJvfZxC4oZZXBQA8f3X3yW9z+UB4BfUNm Z9AkfzR8+j8RwkQboW9KXsQJgBrYFbtTtWB5M5HSsdyoVlRGpXQs4lne1v6dXYJy7knm wOaUj/QcbMClmqySU7HTM4F2vb9ZVeKC048vlZIg8KTfZUU7Ark1A9guAi1Ma3evXcfy d4zw==
X-Gm-Message-State: AOAM531XK26k7UN2xXfrHM+84BYCUl9vOzEBKx5tYYKY6W/m7AM4wZEv eAgEocyYnCky2O4NylR0dEY8e2eE8e8HCEdVTlc=
X-Google-Smtp-Source: ABdhPJyR6BDwMYUAR82VxARhGg7zNemWZKyxVYAmCAlTKO9/awz2HPIGeh1+6GBXrEq3hQJqOoxnSeJggJ5N+rrQRJo=
X-Received: by 2002:adf:e7c2:: with SMTP id e2mr884231wrn.179.1594840448034; Wed, 15 Jul 2020 12:14:08 -0700 (PDT)
MIME-Version: 1.0
References: <CADNypP-CTbXYnmmgxEEVkHEXgtN5JnYSfS5KZvhogGvHrppkjA@mail.gmail.com> <CAD9ie-suSMcc9kzcAdvkrsXNaO2r0_Fp7HKTZenaVaqs9Uz4Jw@mail.gmail.com> <CAJot-L0wYMMkUDjEbn3O50_A-Ly03ASdz=UhU_yZuLaayN3mpA@mail.gmail.com>
In-Reply-To: <CAJot-L0wYMMkUDjEbn3O50_A-Ly03ASdz=UhU_yZuLaayN3mpA@mail.gmail.com>
From: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
Date: Wed, 15 Jul 2020 15:13:56 -0400
Message-ID: <CADNypP90sFBDL80EdzNN-HXJuS4LTC29So0nWieSHFqADEab6Q@mail.gmail.com>
To: Warren Parad <wparad@rhosys.ch>
Cc: Dick Hardt <dick.hardt@gmail.com>, oauth <oauth@ietf.org>
Content-Type: multipart/related; boundary="00000000000061844c05aa7fbaf3"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/7SyOWmc8XIUoXdP7fWFKh82PNDQ>
Subject: Re: [OAUTH-WG] Call for adoption - OAuth 2.1 document
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2020 19:14:20 -0000
Warren, Please, start a separate thread for this issue. Regards, Rifaat On Wed, Jul 15, 2020 at 2:57 PM Warren Parad <wparad@rhosys.ch> wrote: > I only recently joined this WG DL, so maybe this was already discussed by > I have two things I'm confused/curious about: > > 1. Can we avoid using (1, 2, 3) on the left side of the diagram to > describe, I'm not even sure what they are supposed to represent, not to > mention the RO in the diagram doesn't really provide value (for me) > relevant to the code grant flow. It's confusing to see these numerical > identifiers twice in the same picture. But maybe there is something hidden > in this that I'm missing, still 3a and 3b could be used to identify > different legs of the same code path. > [image: image.png] > > 2. It seems recently more and more common to pass the access_token to some > RS via a cookie, yet 7.2.1 says it defines two methods. I think we need > some RFC2119 > <https://www.ietf.org/id/draft-parecki-oauth-v2-1-03.html#RFC2119> keywords > here, to suggest that either SHOULD use one of these two, or MUST. And then > optionally state whether or not we recommend or reject the use of cookies > as a place for access tokens. It's also possible that the language threw me > off, because would an access token in a cookie be a bearer token, but no > matter, if I'm having this thought, then surely others have it as well, > right? > > [image: image.png] > > > *Warren Parad* > Secure your user data and complete your authorization architecture. > Implement Authress <https://bit.ly/37SSO1p>. > <https://rhosys.ch> > > > On Wed, Jul 15, 2020 at 7:55 PM Dick Hardt <dick.hardt@gmail.com> wrote: > >> +1 >> >> On Wed, Jul 15, 2020 at 10:42 AM Rifaat Shekh-Yusef < >> rifaat.s.ietf@gmail.com> wrote: >> >>> All, >>> >>> This is a *call for adoption* for the following *OAuth 2.1* document as >>> a WG document: >>> https://www.ietf.org/id/draft-parecki-oauth-v2-1-03.html >>> >>> Please, provide your feedback on the mailing list by *July 29th.* >>> >>> Regards, >>> Rifaat & Hannes >>> >>> _______________________________________________ >>> OAuth mailing list >>> OAuth@ietf.org >>> https://www.ietf.org/mailman/listinfo/oauth >>> >> _______________________________________________ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> >
- [OAUTH-WG] Call for adoption - OAuth 2.1 document Rifaat Shekh-Yusef
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Dick Hardt
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Warren Parad
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Aaron Parecki
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Rifaat Shekh-Yusef
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Neil Madden
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… John Bradley
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Torsten Lodderstedt
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Michael A Peck
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Falk Andreas
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Hans Zandbelt
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Sascha Preibisch
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… vittorio.bertocci
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… William Denniss
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Dominick Baier
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Jim Willeke
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Daniel Fett
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Dave Tonge
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Vladimir Dzhuvinov
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Nat Sakimura
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Rifaat Shekh-Yusef
- Re: [OAUTH-WG] Call for adoption - OAuth 2.1 docu… Sascha Preibisch