Return-Path: <phil.hunt@oracle.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id E38391B38B3
 for <oauth@ietfa.amsl.com>; Mon, 25 Jan 2016 10:35:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.201
X-Spam-Level: 
X-Spam-Status: No, score=-6.201 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, GB_I_LETTER=-2, HTML_MESSAGE=0.001,
 RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001]
 autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 5pIgTZYoIxS4 for <oauth@ietfa.amsl.com>;
 Mon, 25 Jan 2016 10:35:31 -0800 (PST)
Received: from aserp1040.oracle.com (aserp1040.oracle.com [141.146.126.69])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 3519E1B38B8
 for <oauth@ietf.org>; Mon, 25 Jan 2016 10:35:29 -0800 (PST)
Received: from userv0022.oracle.com (userv0022.oracle.com [156.151.31.74])
 by aserp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id
 u0PIZOtD018736
 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK);
 Mon, 25 Jan 2016 18:35:25 GMT
Received: from userv0122.oracle.com (userv0122.oracle.com [156.151.31.75])
 by userv0022.oracle.com (8.14.4/8.13.8) with ESMTP id u0PIZNFs015966
 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL);
 Mon, 25 Jan 2016 18:35:23 GMT
Received: from abhmp0001.oracle.com (abhmp0001.oracle.com [141.146.116.7])
 by userv0122.oracle.com (8.14.4/8.13.8) with ESMTP id u0PIZNZT007787;
 Mon, 25 Jan 2016 18:35:23 GMT
Received: from [192.168.1.22] (/174.7.250.104)
 by default (Oracle Beehive Gateway v4.0)
 with ESMTP ; Mon, 25 Jan 2016 10:35:22 -0800
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_0EBD37B6-95B8-4B57-A6FC-67A65421D897"
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
From: Phil Hunt <phil.hunt@oracle.com>
In-Reply-To: <56A12010.6090700@aol.com>
Date: Mon, 25 Jan 2016 10:35:18 -0800
Message-Id: <790CD065-F04F-47EF-BFAD-ECE658ACC780@oracle.com>
References: <569E2231.1010107@gmx.net>
 <CAGBSGjpwZ929ZZHYiNpvqLvMDBrVFWaffZLQPwZn_xj7phsrpw@mail.gmail.com>
 <6ADAA1B5-7EF9-49EA-A3D9-6EFC57275EB9@ve7jtb.com>
 <CA+k3eCS1ifU+QJyFtA=gOjSneg3Vh=3bf0CjnEijKTy=-9_xsw@mail.gmail.com>
 <E0918F9D-CA19-47F7-9A87-EBBA55A0B481@ve7jtb.com>
 <CABzCy2BKZ-2GXrgD7FuvTSQ9DB2xYU1URDMBTpmhdG-NwMDc7A@mail.gmail.com>
 <9062E913-39FB-4610-80FE-70796CBDEAC1@ve7jtb.com>
 <BN3PR0301MB1234046860E5CD9E774DB473A6C30@BN3PR0301MB1234.namprd03.prod.outlook.com>
 <CAAP42hDF4XKcyqOpNxMCfs=HLh46QNOk-octWda2bMiJHMXR4Q@mail.gmail.com>
 <F1D3D0C8-7908-4B24-ADDF-1CF4836180B9@adm.umu.se> <56A12010.6090700@aol.com>
To: George Fletcher <gffletch@aol.com>
X-Mailer: Apple Mail (2.3112)
X-Source-IP: userv0022.oracle.com [156.151.31.74]
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/FyqP6H8JXsnnlHm8DWnCh1Kmfuo>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Call for adoption: OAuth 2.0 for Native Apps
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2016 18:35:35 -0000


--Apple-Mail=_0EBD37B6-95B8-4B57-A6FC-67A65421D897
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

+1. I think this helps clarify some mis-conceptions that are out there.

Phil

@independentid
www.independentid.com =
<http://www.independentid.com/>phil.hunt@oracle.com =
<mailto:phil.hunt@oracle.com>





> On Jan 21, 2016, at 10:14 AM, George Fletcher <gffletch@aol.com> =
wrote:
>=20
> I'm also +1 for adoption
>=20
> On 1/21/16 2:56 AM, Roland Hedberg wrote:
>> +1 for adoption
>>=20
>>> 21 jan 2016 kl. 07:11 skrev William Denniss <wdenniss@google.com> =
<mailto:wdenniss@google.com>:
>>>=20
>>> I believe this is important work.
>>>=20
>>> The original OAuth 2 spec left the topic of native apps largely =
undefined which is fair enough, the mobile-first revolution had yet to =
really take hold and people didn't have much implementation experience =
for OAuth on mobile. But we've come a long way since then, we have the =
experience now and I think there is a need for leadership in this space, =
and that it makes sense for the OAUTH-WG to continue our work and =
provide that leadership.
>>>=20
>>> The risk of not defining a best practice for native apps is dilution =
of the open standards =E2=80=93 if everyone implements OAuth differently =
for native apps, and RPs have to write IDP-specific code then what is =
the point of having OAuth as a standard in the first place? Security is =
a major concern as well, there are a lot of ways to mess this up and the =
security situation for OAuth in many native apps is not nearly as good =
as it could be.
>>>=20
>>> By providing leadership in the form of a working group document, we =
can present community advice with the hope that IDPs and RPs alike will =
follow our recommendations, resulting in more interoperability, better =
usability and higher security.
>>>=20
>>> The best part about this spec is that it's pure OAuth! Just wrapped =
with some native app specific recommendations for both RPs and IDPs, to =
achieve the desired levels of usability and security on mobile.
>>>=20
>>> I will point out that we have rough consensus and running code. The =
rough consensus can be seen from the WG votes, and the sentiment on this =
thread (your dissenting opinion notwithstanding). Regarding running =
code, my team is in the process of open sourcing libraries that will =
implement this best practice to the letter (and the code's already =
running, I assure you). The proprietary Google Sign-in and Facebook =
Sign-in SDKs are also using in-app browser tabs for OAuth flows in =
production today, which I think is further evidence that this is a =
viable pattern.
>>>=20
>>> This document and proposal was never part of the OpenID working =
group that you refer to below.
>>>=20
>>> I'm not saying the document is perfect, and it is definitely in need =
of an update! But I'm committed to listening to the community and taking =
it forward. Now that the dependencies have launched, and our library =
implementations are done, I plan to update the doc with the feedback =
from this community, and the lessons we and others have learnt from our =
implementations.
>>>=20
>>> I hope the working group will consider adopting this document.
>>>=20
>>> Kind Regards,
>>> William
>>>=20
>>>=20
>>> On Thu, Jan 21, 2016 at 12:33 PM, Anthony Nadalin =
<tonynad@microsoft.com> <mailto:tonynad@microsoft.com> wrote:
>>> This work had many issues in the OpenID WG where it failed why =
should this be a WG item here ? The does meet the requirements for =
experimental, there is a fine line between informational and =
experimental, I would be OK with either but prefer experimental, I =
don=E2=80=99t think that this should become a standard.
>>>=20
>>>=20
>>>=20
>>> From: OAuth [mailto:oauth-bounces@ietf.org =
<mailto:oauth-bounces@ietf.org>] On Behalf Of John Bradley
>>> Sent: Wednesday, January 20, 2016 12:11 PM
>>> To: Nat Sakimura <sakimura@gmail.com> <mailto:sakimura@gmail.com>
>>> Cc: oauth@ietf.org <mailto:oauth@ietf.org>
>>> Subject: Re: [OAUTH-WG] Call for adoption: OAuth 2.0 for Native Apps
>>>=20
>>>=20
>>>=20
>>> PS as you probably suspected I am in favour of moving this forward.
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>> On Jan 20, 2016, at 5:08 PM, Nat Sakimura <sakimura@gmail.com> =
<mailto:sakimura@gmail.com> wrote:
>>>=20
>>>=20
>>>=20
>>> +1 for moving this forward.
>>>=20
>>> 2016=E5=B9=B41=E6=9C=8821=E6=97=A5=E6=9C=A8=E6=9B=9C=E6=97=A5=E3=80=81=
John Bradley<ve7jtb@ve7jtb.com> =
<mailto:ve7jtb@ve7jtb.com>=E3=81=95=E3=82=93=E3=81=AF=E6=9B=B8=E3=81=8D=E3=
=81=BE=E3=81=97=E3=81=9F:
>>>=20
>>> Yes more is needed.   It was theoretical at that point.  Now we have =
implementation experience.
>>>=20
>>>=20
>>>=20
>>> On Jan 20, 2016, at 3:38 PM, Brian Campbell =
<bcampbell@pingidentity.com> <mailto:bcampbell@pingidentity.com> wrote:
>>>=20
>>>=20
>>>=20
>>> There is =
https://tools.ietf.org/html/draft-wdenniss-oauth-native-apps-00#appendix-A=
 =
<https://tools.ietf.org/html/draft-wdenniss-oauth-native-apps-00#appendix-=
A> which has some mention of SFSafariViewController and Chrome Custom =
Tabs.
>>>=20
>>> Maybe more is needed?
>>>=20
>>>=20
>>>=20
>>> On Wed, Jan 20, 2016 at 10:45 AM, John Bradley <ve7jtb@ve7jtb.com> =
<mailto:ve7jtb@ve7jtb.com> wrote:
>>>=20
>>> Yes, in July we recommended using the system browser rather than =
WebViews.
>>>=20
>>>=20
>>>=20
>>> About that time Apple announced Safari view controller and Google =
Chrome custom tabs.   The code in the OS is now stable and we have done =
a fair amount of testing.
>>>=20
>>>=20
>>>=20
>>> The OIDF will shortly be publishing reference libraries for iOS and =
Android to how how to best use View Controllers, and PKCE in native apps =
on those platforms.
>>>=20
>>>=20
>>>=20
>>> We do need to update this doc to reflect what we have learned in the =
last 6 months.
>>>=20
>>>=20
>>>=20
>>> One problem we do still have is not having someone with Win 10 =
mobile experience to help document the best practices for that platform.
>>>=20
>>> I don=E2=80=99t understand that platform well enough yet to include =
anything.
>>>=20
>>>=20
>>>=20
>>> John B.
>>>=20
>>>=20
>>>=20
>>> On Jan 20, 2016, at 12:40 PM, Aaron Parecki <aaron@parecki.com> =
<mailto:aaron@parecki.com> wrote:
>>>=20
>>>=20
>>>=20
>>> The section on embedded web views doesn't mention the new iOS 9 =
SFSafariViewController which allows apps to display a system browser =
within the application. The new API doesn't give the calling application =
access to anything inside the browser, so it is acceptable for using =
with OAuth flows. I think it's important to mention this new capability =
for apps to leverage since it leads to a better user experience.
>>>=20
>>>=20
>>>=20
>>> I'm sure that can be addressed in the coming months if this document =
is just the starting point.
>>>=20
>>>=20
>>>=20
>>> I definitely agree that a document about native apps is necessary =
since the core leaves a lot of guessing room for an implementation.
>>>=20
>>>=20
>>>=20
>>> For reference, =
https://developer.apple.com/library/prerelease/ios/releasenotes/General/Wh=
atsNewIniOS/Articles/iOS9.html#//apple_ref/doc/uid/TP40016198-DontLinkElem=
entID_26 =
<https://developer.apple.com/library/prerelease/ios/releasenotes/General/W=
hatsNewIniOS/Articles/iOS9.html#//apple_ref/doc/uid/TP40016198-DontLinkEle=
mentID_26>
>>>=20
>>>=20
>>>=20
>>> And see the attached screenshot for an example of what it looks =
like.
>>>=20
>>>=20
>>>=20
>>> <embedded-oauth-view.png>
>>>=20
>>>=20
>>>=20
>>> ----
>>>=20
>>> Aaron Parecki
>>>=20
>>> aaronparecki.com
>>>=20
>>> @aaronpk
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>> On Tue, Jan 19, 2016 at 3:46 AM, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> <mailto:hannes.tschofenig@gmx.net> wrote:
>>>=20
>>> Hi all,
>>>=20
>>> this is the call for adoption of OAuth 2.0 for Native Apps, see
>>> http://datatracker.ietf.org/doc/draft-wdenniss-oauth-native-apps/ =
<http://datatracker.ietf.org/doc/draft-wdenniss-oauth-native-apps/>
>>>=20
>>> Please let us know by Feb 2nd whether you accept / object to the
>>> adoption of this document as a starting point for work in the OAuth
>>> working group.
>>>=20
>>> Note: If you already stated your opinion at the IETF meeting in =
Yokohama
>>> then you don't need to re-state your opinion, if you want.
>>>=20
>>> The feedback at the Yokohama IETF meeting was the following: 16 =
persons
>>> for doing the work / 0 persons against / 2 persons need more info
>>>=20
>>> Ciao
>>> Hannes & Derek
>>>=20
>>>=20
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>>>=20
>>>=20
>>>=20
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>>>=20
>>>=20
>>>=20
>>>=20
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>> --
>>> Nat Sakimura (=3Dnat)
>>>=20
>>> Chairman, OpenID Foundation
>>> http://nat.sakimura.org/ <http://nat.sakimura.org/>
>>> @_nat_en
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>>>=20
>>>=20
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>>=20
>>=20
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>> https://www.ietf.org/mailman/listinfo/oauth =
<https://www.ietf.org/mailman/listinfo/oauth>
>=20
> --=20
> Chief Architect                  =20
> Identity Services Engineering     Work: george.fletcher@teamaol.com =
<mailto:george.fletcher@teamaol.com>
> AOL Inc.                          AIM:  gffletch
> Mobile: +1-703-462-3494           Twitter: http://twitter.com/gffletch =
<http://twitter.com/gffletch>
> Office: +1-703-265-2544           Photos: =
http://georgefletcher.photography <http://georgefletcher.photography/>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth


--Apple-Mail=_0EBD37B6-95B8-4B57-A6FC-67A65421D897
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">+1. I think this helps clarify some mis-conceptions that are =
out there.<div class=3D""><br class=3D""><div class=3D"">
<div style=3D"color: rgb(0, 0, 0); letter-spacing: normal; orphans: =
auto; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><div style=3D"color: rgb(0, 0, 0); letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><div class=3D""><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; line-height: normal; border-spacing: =
0px;"><div class=3D"" style=3D"word-wrap: break-word; -webkit-nbsp-mode: =
space; -webkit-line-break: after-white-space;"><div class=3D""><div =
class=3D""><div class=3D"">Phil</div><div class=3D""><br =
class=3D""></div><div class=3D"">@independentid</div><div class=3D""><a =
href=3D"http://www.independentid.com" =
class=3D"">www.independentid.com</a></div></div></div></div></span><a =
href=3D"mailto:phil.hunt@oracle.com" class=3D"" style=3D"orphans: 2; =
widows: 2;">phil.hunt@oracle.com</a></div><div class=3D""><br =
class=3D""></div></div><br class=3D"Apple-interchange-newline"></div><br =
class=3D"Apple-interchange-newline"><br =
class=3D"Apple-interchange-newline">
</div>
<br class=3D""><div style=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Jan 21, 2016, at 10:14 AM, George Fletcher &lt;<a =
href=3D"mailto:gffletch@aol.com" class=3D"">gffletch@aol.com</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D"">
 =20
    <meta content=3D"text/html; charset=3DUTF-8" =
http-equiv=3D"Content-Type" class=3D"">
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000" class=3D"">
    <font face=3D"Helvetica, Arial, sans-serif" class=3D"">I'm also +1 =
for adoption</font><br class=3D"">
    <br class=3D"">
    <div class=3D"moz-cite-prefix">On 1/21/16 2:56 AM, Roland Hedberg
      wrote:<br class=3D"">
    </div>
    <blockquote =
cite=3D"mid:F1D3D0C8-7908-4B24-ADDF-1CF4836180B9@adm.umu.se" type=3D"cite"=
 class=3D"">
      <pre wrap=3D"" class=3D"">+1 for adoption

</pre>
      <blockquote type=3D"cite" class=3D"">
        <pre wrap=3D"" class=3D"">21 jan 2016 kl. 07:11 skrev William =
Denniss <a class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:wdenniss@google.com">&lt;wdenniss@google.com&gt;</a>:

I believe this is important work.

The original OAuth 2 spec left the topic of native apps largely =
undefined which is fair enough, the mobile-first revolution had yet to =
really take hold and people didn't have much implementation experience =
for OAuth on mobile. But we've come a long way since then, we have the =
experience now and I think there is a need for leadership in this space, =
and that it makes sense for the OAUTH-WG to continue our work and =
provide that leadership.

The risk of not defining a best practice for native apps is dilution of =
the open standards =E2=80=93 if everyone implements OAuth differently =
for native apps, and RPs have to write IDP-specific code then what is =
the point of having OAuth as a standard in the first place? Security is =
a major concern as well, there are a lot of ways to mess this up and the =
security situation for OAuth in many native apps is not nearly as good =
as it could be.

By providing leadership in the form of a working group document, we can =
present community advice with the hope that IDPs and RPs alike will =
follow our recommendations, resulting in more interoperability, better =
usability and higher security.

The best part about this spec is that it's pure OAuth! Just wrapped with =
some native app specific recommendations for both RPs and IDPs, to =
achieve the desired levels of usability and security on mobile.

I will point out that we have rough consensus and running code. The =
rough consensus can be seen from the WG votes, and the sentiment on this =
thread (your dissenting opinion notwithstanding). Regarding running =
code, my team is in the process of open sourcing libraries that will =
implement this best practice to the letter (and the code's already =
running, I assure you). The proprietary Google Sign-in and Facebook =
Sign-in SDKs are also using in-app browser tabs for OAuth flows in =
production today, which I think is further evidence that this is a =
viable pattern.

This document and proposal was never part of the OpenID working group =
that you refer to below.

I'm not saying the document is perfect, and it is definitely in need of =
an update! But I'm committed to listening to the community and taking it =
forward. Now that the dependencies have launched, and our library =
implementations are done, I plan to update the doc with the feedback =
from this community, and the lessons we and others have learnt from our =
implementations.

I hope the working group will consider adopting this document.

Kind Regards,
William


On Thu, Jan 21, 2016 at 12:33 PM, Anthony Nadalin <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:tonynad@microsoft.com">&lt;tonynad@microsoft.com&gt;</a> =
wrote:
This work had many issues in the OpenID WG where it failed why should =
this be a WG item here ? The does meet the requirements for =
experimental, there is a fine line between informational and =
experimental, I would be OK with either but prefer experimental, I =
don=E2=80=99t think that this should become a standard.



From: OAuth [<a class=3D"moz-txt-link-freetext" =
href=3D"mailto:oauth-bounces@ietf.org">mailto:oauth-bounces@ietf.org</a>] =
On Behalf Of John Bradley
Sent: Wednesday, January 20, 2016 12:11 PM
To: Nat Sakimura <a class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:sakimura@gmail.com">&lt;sakimura@gmail.com&gt;</a>
Cc: <a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:oauth@ietf.org">oauth@ietf.org</a>
Subject: Re: [OAUTH-WG] Call for adoption: OAuth 2.0 for Native Apps



PS as you probably suspected I am in favour of moving this forward.





On Jan 20, 2016, at 5:08 PM, Nat Sakimura <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:sakimura@gmail.com">&lt;sakimura@gmail.com&gt;</a> wrote:



+1 for moving this forward.

2016=E5=B9=B41=E6=9C=8821=E6=97=A5=E6=9C=A8=E6=9B=9C=E6=97=A5=E3=80=81John=
 Bradley<a class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:ve7jtb@ve7jtb.com">&lt;ve7jtb@ve7jtb.com&gt;</a>=E3=81=95=E3=
=82=93=E3=81=AF=E6=9B=B8=E3=81=8D=E3=81=BE=E3=81=97=E3=81=9F:

Yes more is needed.   It was theoretical at that point.  Now we have =
implementation experience.



On Jan 20, 2016, at 3:38 PM, Brian Campbell <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:bcampbell@pingidentity.com">&lt;bcampbell@pingidentity.com&=
gt;</a> wrote:



There is <a class=3D"moz-txt-link-freetext" =
href=3D"https://tools.ietf.org/html/draft-wdenniss-oauth-native-apps-00#ap=
pendix-A">https://tools.ietf.org/html/draft-wdenniss-oauth-native-apps-00#=
appendix-A</a> which has some mention of SFSafariViewController and =
Chrome Custom Tabs.

Maybe more is needed?



On Wed, Jan 20, 2016 at 10:45 AM, John Bradley <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:ve7jtb@ve7jtb.com">&lt;ve7jtb@ve7jtb.com&gt;</a> wrote:

Yes, in July we recommended using the system browser rather than =
WebViews.



About that time Apple announced Safari view controller and Google Chrome =
custom tabs.   The code in the OS is now stable and we have done a fair =
amount of testing.



The OIDF will shortly be publishing reference libraries for iOS and =
Android to how how to best use View Controllers, and PKCE in native apps =
on those platforms.



We do need to update this doc to reflect what we have learned in the =
last 6 months.



One problem we do still have is not having someone with Win 10 mobile =
experience to help document the best practices for that platform.

I don=E2=80=99t understand that platform well enough yet to include =
anything.



John B.



On Jan 20, 2016, at 12:40 PM, Aaron Parecki <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:aaron@parecki.com">&lt;aaron@parecki.com&gt;</a> wrote:



The section on embedded web views doesn't mention the new iOS 9 =
SFSafariViewController which allows apps to display a system browser =
within the application. The new API doesn't give the calling application =
access to anything inside the browser, so it is acceptable for using =
with OAuth flows. I think it's important to mention this new capability =
for apps to leverage since it leads to a better user experience.



I'm sure that can be addressed in the coming months if this document is =
just the starting point.



I definitely agree that a document about native apps is necessary since =
the core leaves a lot of guessing room for an implementation.



For reference, <a class=3D"moz-txt-link-freetext" =
href=3D"https://developer.apple.com/library/prerelease/ios/releasenotes/Ge=
neral/WhatsNewIniOS/Articles/iOS9.html#//apple_ref/doc/uid/TP40016198-Dont=
LinkElementID_26">https://developer.apple.com/library/prerelease/ios/relea=
senotes/General/WhatsNewIniOS/Articles/iOS9.html#//apple_ref/doc/uid/TP400=
16198-DontLinkElementID_26</a>



And see the attached screenshot for an example of what it looks like.



&lt;embedded-oauth-view.png&gt;



----

Aaron Parecki

<a href=3D"http://aaronparecki.com" class=3D"">aaronparecki.com</a>

@aaronpk





On Tue, Jan 19, 2016 at 3:46 AM, Hannes Tschofenig <a =
class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:hannes.tschofenig@gmx.net">&lt;hannes.tschofenig@gmx.net&gt=
;</a> wrote:

Hi all,

this is the call for adoption of OAuth 2.0 for Native Apps, see
<a class=3D"moz-txt-link-freetext" =
href=3D"http://datatracker.ietf.org/doc/draft-wdenniss-oauth-native-apps/"=
>http://datatracker.ietf.org/doc/draft-wdenniss-oauth-native-apps/</a>

Please let us know by Feb 2nd whether you accept / object to the
adoption of this document as a starting point for work in the OAuth
working group.

Note: If you already stated your opinion at the IETF meeting in Yokohama
then you don't need to re-state your opinion, if you want.

The feedback at the Yokohama IETF meeting was the following: 16 persons
for doing the work / 0 persons against / 2 persons need more info

Ciao
Hannes &amp; Derek


_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>



_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>




_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>







--
Nat Sakimura (=3Dnat)

Chairman, OpenID Foundation
<a class=3D"moz-txt-link-freetext" =
href=3D"http://nat.sakimura.org/">http://nat.sakimura.org/</a>
@_nat_en






_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>


_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>
</pre>
      </blockquote>
      <pre wrap=3D"" class=3D""></pre>
      <br class=3D"">
      <fieldset class=3D"mimeAttachmentHeader"></fieldset>
      <br class=3D"">
      <pre wrap=3D"" =
class=3D"">_______________________________________________
OAuth mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a>
</pre>
    </blockquote>
    <br class=3D"">
    <pre class=3D"moz-signature" cols=3D"72">--=20
Chief Architect                  =20
Identity Services Engineering     Work: <a =
class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:george.fletcher@teamaol.com">george.fletcher@teamaol.com</a=
>
AOL Inc.                          AIM:  gffletch
Mobile: +1-703-462-3494           Twitter: <a =
class=3D"moz-txt-link-freetext" =
href=3D"http://twitter.com/gffletch">http://twitter.com/gffletch</a>
Office: +1-703-265-2544           Photos: <a =
class=3D"moz-txt-link-freetext" =
href=3D"http://georgefletcher.photography/">http://georgefletcher.photogra=
phy</a>
</pre>
  </div>

_______________________________________________<br class=3D"">OAuth =
mailing list<br class=3D""><a href=3D"mailto:OAuth@ietf.org" =
class=3D"">OAuth@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/oauth<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_0EBD37B6-95B8-4B57-A6FC-67A65421D897--

