Re: [OAUTH-WG] Quick survey: fragment vs. query
Oleg Gryb <oleg_gryb@yahoo.com> Tue, 10 August 2010 16:34 UTC
Return-Path: <oleg_gryb@yahoo.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 62DFD3A6984 for <oauth@core3.amsl.com>; Tue, 10 Aug 2010 09:34:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.427
X-Spam-Level:
X-Spam-Status: No, score=-1.427 tagged_above=-999 required=5 tests=[AWL=-0.688, BAYES_20=-0.74, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kyDMZLn53Ueb for <oauth@core3.amsl.com>; Tue, 10 Aug 2010 09:34:41 -0700 (PDT)
Received: from web37602.mail.mud.yahoo.com (web37602.mail.mud.yahoo.com [209.191.87.85]) by core3.amsl.com (Postfix) with SMTP id 9D77B3A6888 for <oauth@ietf.org>; Tue, 10 Aug 2010 09:34:40 -0700 (PDT)
Received: (qmail 77664 invoked by uid 60001); 10 Aug 2010 16:35:05 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1281458105; bh=1DyiPILA3ZOhadxlpbACmXectegzneDeL1rxiQ3NSP8=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type; b=Jfo1oLetAlAu9dIds2mkgM9Z+lV/UIqbggyriz79UvaeJm5B8k6wlbwVn3GTEa634Af7j2IO1BgLvgBV/UHS7bzVzUygRicSCe6MHv4SmlhuCaF/uRzwoS8LDGviJBOfnn3Wd/G21KnbbMr2vfO77GMM/XRgU/fqWjMWALulGj8=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type; b=b0l3Oybl9eR9CTdCw3+69YML33eAR+SMJv49XjXrX8jMH4FDLyt2IRiE6texUCo+RwCruAOdML+FGbTmcwdFnDvGdZBhuXnX+TbTfDNuaI53PV8ZHU1VVT/sgydCbANRvjODhVVUjJHIkL/L8b//3UeqWj4cBjvZElB1Tmb6jO4=;
Message-ID: <837544.77407.qm@web37602.mail.mud.yahoo.com>
X-YMail-OSG: gJNK_v4VM1mgUL8zmdb677jRuSwk8Jt.wmHvHFIQ._BPUid fKYMNg76mOlyWhuqOo8QH1iegYWOuvm3FH5efb_T2KtIR3iniJeU2osIYSln jBUY1Xm9TfAYQ9CdWl_Rk.A5ofV30N2yoGyyr2EvAAyhBDoNKSlQ8BQd7Pko Lfq3xX8Ju37LTsg5v45ly4LT3rsD7w_dR7mIYu4PXgi5rDoVTEpXgOfaW5If TQBVCkyj49iFp8cI4gPAX1aXmv2JeWOBnZcyYtTTRA2MVhyycS_tHbMc4seV TiVReEW7sE_gziakYPEvMy9y5vNdmko21sQR1oYvPooOS0_csQPJmyyzZbEu NHe3umWZ.h2psRdD7qPwJ4vNhkwpM5hV6J3QG9bnHeQ--
Received: from [208.240.243.170] by web37602.mail.mud.yahoo.com via HTTP; Tue, 10 Aug 2010 09:35:05 PDT
X-Mailer: YahooMailRC/459 YahooMailWebService/0.8.105.279950
References: <C862F736.37253%eran@hueniverse.com> <AANLkTil_MQ1-JxNC-5S3bLDo6-WhG0GMBHVXQvvN-jdv@mail.gmail.com> <AANLkTi=A+ztAH8vbR-O8vYUxiE2cGjn-KHCpM05NE3fL@mail.gmail.com> <8F6F3A55-274C-4F38-84C8-C956D74504AE@lodderstedt.net>
Date: Tue, 10 Aug 2010 09:35:05 -0700
From: Oleg Gryb <oleg_gryb@yahoo.com>
To: Torsten Lodderstedt <torsten@lodderstedt.net>, David Recordon <recordond@gmail.com>
In-Reply-To: <8F6F3A55-274C-4F38-84C8-C956D74504AE@lodderstedt.net>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1592294065-1281458105=:77407"
Cc: Naitik Shah <naitik@facebook.com>, OAuth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Quick survey: fragment vs. query
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Oleg Gryb <oleg@gryb.info>
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Aug 2010 16:34:43 -0000
I was trying to understand that too (see "Is user agent profile secure" thread).
The answers that I've got were:
1. It's already coded this way.
2. It's the most efficient way of doing that, because that relay.html page is
static and can be cached by a browser.
None of the answers above looks very convincing to me, but that's where UA is
now.
From: Torsten Lodderstedt <torsten@lodderstedt.net>
Can someone pls. explain why code and token should both be returned in the
fragment?
>
>
>
>regards,
>Torsten.
>
- [OAUTH-WG] Quick survey: fragment vs. query Eran Hammer-Lahav
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query David Recordon
- Re: [OAUTH-WG] Quick survey: fragment vs. query Naitik Shah
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Zeltsan, Zachary (Zachary)
- Re: [OAUTH-WG] Quick survey: fragment vs. query Eran Hammer-Lahav
- Re: [OAUTH-WG] Quick survey: fragment vs. query Eran Hammer-Lahav
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Luke Shepard
- Re: [OAUTH-WG] Quick survey: fragment vs. query David Recordon
- Re: [OAUTH-WG] Quick survey: fragment vs. query Naitik Shah
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Oleg Gryb
- Re: [OAUTH-WG] Quick survey: fragment vs. query Luke Shepard
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Oleg Gryb
- Re: [OAUTH-WG] Quick survey: fragment vs. query David Recordon
- Re: [OAUTH-WG] Quick survey: fragment vs. query Gryb, Oleg
- Re: [OAUTH-WG] Quick survey: fragment vs. query Torsten Lodderstedt
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Oleg Gryb
- Re: [OAUTH-WG] Quick survey: fragment vs. query Brian Eaton
- Re: [OAUTH-WG] Quick survey: fragment vs. query Eran Hammer-Lahav