Re: [OAUTH-WG] New OAuth for Browser-Based Apps draft -02

Torsten Lodderstedt <torsten@lodderstedt.net> Thu, 25 July 2019 18:59 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0ACE3120191 for <oauth@ietfa.amsl.com>; Thu, 25 Jul 2019 11:59:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c5wuzxefSG7x for <oauth@ietfa.amsl.com>; Thu, 25 Jul 2019 11:59:23 -0700 (PDT)
Received: from smtprelay02.ispgateway.de (smtprelay02.ispgateway.de [80.67.18.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4BA5F12019F for <oauth@ietf.org>; Thu, 25 Jul 2019 11:59:23 -0700 (PDT)
Received: from [91.13.158.20] (helo=[192.168.71.102]) by smtprelay02.ispgateway.de with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92) (envelope-from <torsten@lodderstedt.net>) id 1hqixT-0003na-EY; Thu, 25 Jul 2019 20:59:19 +0200
Content-Type: multipart/signed; boundary=Apple-Mail-FA10D27C-6DC4-49D3-957E-357DE86E1569; protocol="application/pkcs7-signature"; micalg=sha-256
Mime-Version: 1.0 (1.0)
From: Torsten Lodderstedt <torsten@lodderstedt.net>
X-Mailer: iPhone Mail (16F203)
In-Reply-To: <CAGBSGjpXrE+s2PXv8yMBCpbYsJXtF=m3t-sfbVrD3Uy7NV6EDQ@mail.gmail.com>
Date: Thu, 25 Jul 2019 20:59:18 +0200
Cc: Tomek Stojecki <tstojecki=40yahoo.com@dmarc.ietf.org>, Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>, OAuth WG <oauth@ietf.org>
Content-Transfer-Encoding: 7bit
Message-Id: <0C46E46C-5027-47E7-8214-A4F865127B9C@lodderstedt.net>
References: <CAGBSGjqVV3jJaXEX28N_fKbLSp3ijzb34N9NrZwZ+ZNXwXGKAg@mail.gmail.com> <0C094925-1429-46ED-8CF6-0D7B8DFB332F@lodderstedt.net> <CA+k3eCT5eG=S9AjM7Ss=DwHvsjwnriuZC3_yMxhrUaJXf2-vrw@mail.gmail.com> <99169CD8-F415-43CB-9F93-D779E5A15592@alkaline-solutions.com> <1903519861.188545.1563954610968@mail.yahoo.com> <CAGBSGjpXrE+s2PXv8yMBCpbYsJXtF=m3t-sfbVrD3Uy7NV6EDQ@mail.gmail.com>
To: Aaron Parecki <aaron@parecki.com>
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC5uZXQ=
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Cnzasn-DiKGS2hIWqq4V3wxxhOE>
Subject: Re: [OAUTH-WG] New OAuth for Browser-Based Apps draft -02
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2019 18:59:26 -0000


Am 24.07.2019 um 22:13 schrieb Aaron Parecki <aaron@parecki.com>;:

>> 2) Regarding architectures: I think this BCP should focus on recommendations for securely implementing OAuth in the different potential architecture. I don’t think we should get into the business of recommending and assessing other solutions (e.g. section 6.1.).
> 
> This section was originally added from a discussion on the list, I believe it was actually Torsten's suggestion: https://mailarchive.ietf.org/arch/msg/oauth/JoEjvUrwE3pBPJI1olkEIR7ov9Q The section was later modified and expanded based on feedback from the meeting in Prague.

My latest feedback is inline with the post you refer to. There I suggested to also consider an architecture where the OAuth logic resides in a backend. I never suggested to add anything outside of an OAuth-based architecture.