Re: [OAUTH-WG] Authorization Code Grant diagram Improvement OAuth 2.1 draft-ietf-oauth-v2-1

Aaron Parecki <aaron@parecki.com> Thu, 30 July 2020 15:49 UTC

Return-Path: <aaron@parecki.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 068543A09DD for <oauth@ietfa.amsl.com>; Thu, 30 Jul 2020 08:49:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.692
X-Spam-Level:
X-Spam-Status: No, score=-0.692 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DC_PNG_UNO_LARGO=0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_IMAGE_RATIO_06=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=parecki.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VSU3hPKrsgpp for <oauth@ietfa.amsl.com>; Thu, 30 Jul 2020 08:49:41 -0700 (PDT)
Received: from mail-io1-xd2d.google.com (mail-io1-xd2d.google.com [IPv6:2607:f8b0:4864:20::d2d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C857A3A09DB for <oauth@ietf.org>; Thu, 30 Jul 2020 08:49:31 -0700 (PDT)
Received: by mail-io1-xd2d.google.com with SMTP id j8so16341608ioe.9 for <oauth@ietf.org>; Thu, 30 Jul 2020 08:49:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=parecki.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=ZLAVhEPb9XKQK4/OdGGxITMKIs3RsTsnkUiMRK6RcnA=; b=gnEZLbdg0KNz87ycLxEEi9jSUkokwWhu11YApqqC9keVvBpstaSd6bmBM30wPbo7JH jENCzpuxJtGfBBgZrm6oSV1jDdBW2g7ESZKwrYAKaAO0uKG+z85cw6+E14ug/23gIpzI 661I6P4o7yoSD4d3DrAXXlw9qF9k38Vf49ci0VxKLMmRirTBlsygdifx8tgThhiW8sCT Rw8JZq9gHFfcgiZStbXFsE5usv4ztYvNRFzIt2cCkI/RbASwNW3KpZuQGqJDVtl1KDNE oJSSD9oK7TKQl5CB04rskAMKbi/9mKQRNfy+PAC5+JfTP5Z029cVrenoIASf1AGF+0+c op0Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=ZLAVhEPb9XKQK4/OdGGxITMKIs3RsTsnkUiMRK6RcnA=; b=AB3jRu/Z8f31+xVK+oUw62MayTHdI3bsMRDydH37xWq4AIJaADJy7Uy1UXzOyRACvd fxDktIoImvD8hgbpEZKXOKIUiQZP07dMpIC1fyh8xqd9adpdXwXVaKiHxX8YUoSB7cvN qboUZ5VtUztVcHlWy+N8IiO/OWX9c38PCV+ddPxD6/VNlhHuMQUXAeWNzO0/9DeHpFCg /iY5q2Jx0KmGdn0PiBeccMZQj7t/isxpxFEJih4w7lCD2Y20kBiS4kHxdnNwKA/SRDWR WRgbIP8oxTBTdnTetUbyk+LwnKXJMYOERulae0QA5kPzaxX8hg2WfXUtCTact8Azc0Oe B1jQ==
X-Gm-Message-State: AOAM531BdryhykneIfwYJPau4A34zXcyJYb49fqNjZcln2Sz6YbP1vIy FndVRGbfLhzB+2G6e0yDEL60V5rRU0A=
X-Google-Smtp-Source: ABdhPJx4+zfeWrWRYlQpTrBMGtowMIOr9y5OYJ18bI8L3lWG1BNGbtpfPXifnilXiVsk4ZFLTisbSA==
X-Received: by 2002:a02:6a6b:: with SMTP id m43mr4117104jaf.79.1596124170332; Thu, 30 Jul 2020 08:49:30 -0700 (PDT)
Received: from mail-io1-f41.google.com (mail-io1-f41.google.com. [209.85.166.41]) by smtp.gmail.com with ESMTPSA id b67sm3192806ill.31.2020.07.30.08.49.28 for <oauth@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 30 Jul 2020 08:49:29 -0700 (PDT)
Received: by mail-io1-f41.google.com with SMTP id v6so13450008iow.11 for <oauth@ietf.org>; Thu, 30 Jul 2020 08:49:28 -0700 (PDT)
X-Received: by 2002:a6b:8b86:: with SMTP id n128mr38874448iod.202.1596124168531; Thu, 30 Jul 2020 08:49:28 -0700 (PDT)
MIME-Version: 1.0
References: <CAJot-L0pNWox1aX5GOkD=QVJakRVVtn=PvysciB2Wak6ijG+Dw@mail.gmail.com>
In-Reply-To: <CAJot-L0pNWox1aX5GOkD=QVJakRVVtn=PvysciB2Wak6ijG+Dw@mail.gmail.com>
From: Aaron Parecki <aaron@parecki.com>
Date: Thu, 30 Jul 2020 08:49:17 -0700
X-Gmail-Original-Message-ID: <CAGBSGjo_w5+fOE0bQeeiuQLt0-Xkt+Gdu01C3BHZeuOZNh4Taw@mail.gmail.com>
Message-ID: <CAGBSGjo_w5+fOE0bQeeiuQLt0-Xkt+Gdu01C3BHZeuOZNh4Taw@mail.gmail.com>
To: Warren Parad <wparad@rhosys.ch>
Cc: oauth <oauth@ietf.org>
Content-Type: multipart/related; boundary="000000000000154eb105abaa9e5e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/8a3jGJrFfwNCzcJbc0AqkTg_p88>
Subject: Re: [OAUTH-WG] Authorization Code Grant diagram Improvement OAuth 2.1 draft-ietf-oauth-v2-1
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2020 15:49:43 -0000

These numbers in the diagram correspond to the numbered steps in the
paragraphs below the diagram. Perhaps using non-duplicated numbers would
help, such as "1a" and "1b" instead of two instances of "1"? Although I'm
not sure how that would work exactly because the "1/2/3" are really just a
single action as described by the "Note" below the diagram in your
screenshot.

---
Aaron Parecki
https://aaronparecki.com
https://oauth2simplified.com

On Thu, Jul 30, 2020 at 8:43 AM Warren Parad <wparad@rhosys.ch> wrote:

>
> https://www.ietf.org/id/draft-ietf-oauth-v2-1-00.html#name-authorization-code-grant
>
> Can we avoid using (1, 2, 3) on the left side of the diagram to describe,
> I'm not even sure what they are supposed to represent, not to mention the
> RO in the diagram doesn't really provide value (for me) relevant to the
> code grant flow. It's confusing to see these numerical identifiers twice in
> the same picture. But maybe there is something hidden in this that I'm
> missing, still 3a and 3b could be used to identify different legs of the
> same code path.
> [image: image.png]
>
>
> *Warren Parad*
> Secure your user data and complete your authorization architecture.
> Implement Authress <https://bit..ly/37SSO1p>.
> <https://rhosys.ch>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>