Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review of draft-ietf-oauth-v2-23
ht@inf.ed.ac.uk (Henry S. Thompson) Thu, 08 March 2012 11:45 UTC
Return-Path: <ht@inf.ed.ac.uk>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B21F921F8648; Thu, 8 Mar 2012 03:45:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EZ2943PhRPfp; Thu, 8 Mar 2012 03:45:35 -0800 (PST)
Received: from treacle.ucs.ed.ac.uk (treacle.ucs.ed.ac.uk [129.215.16.102]) by ietfa.amsl.com (Postfix) with ESMTP id 9761F21F8647; Thu, 8 Mar 2012 03:45:34 -0800 (PST)
Received: from nutty.inf.ed.ac.uk (nutty.inf.ed.ac.uk [129.215.33.33]) by treacle.ucs.ed.ac.uk (8.13.8/8.13.4) with ESMTP id q28BifJH019389; Thu, 8 Mar 2012 11:44:46 GMT
Received: from calexico.inf.ed.ac.uk (calexico.inf.ed.ac.uk [129.215.24.15]) by nutty.inf.ed.ac.uk (8.13.8/8.13.8) with ESMTP id q28BiemO013576; Thu, 8 Mar 2012 11:44:40 GMT
Received: from calexico.inf.ed.ac.uk (localhost [127.0.0.1]) by calexico.inf.ed.ac.uk (8.14.4/8.14.4) with ESMTP id q28BiejW003264; Thu, 8 Mar 2012 11:44:40 GMT
Received: (from ht@localhost) by calexico.inf.ed.ac.uk (8.14.4/8.14.4/Submit) id q28BidJX003259; Thu, 8 Mar 2012 11:44:39 GMT
X-Authentication-Warning: calexico.inf.ed.ac.uk: ht set sender to ht@inf.ed.ac.uk using -f
To: Barry Leiba <barryleiba@computer.org>
References: <f5bd39hbayn.fsf@calexico.inf.ed.ac.uk> <90C41DD21FB7C64BB94121FBBC2E723453AFCD4076@P3PW5EX1MB01.EX1.SECURESERVER.NET> <CAC4RtVCnhNqJoaD5BDhamqjaAeHXYmU_gnJ0wn4ay9bVvaPb8A@mail.gmail.com>
From: ht@inf.ed.ac.uk
Date: Thu, 08 Mar 2012 11:44:39 +0000
In-Reply-To: <CAC4RtVCnhNqJoaD5BDhamqjaAeHXYmU_gnJ0wn4ay9bVvaPb8A@mail.gmail.com> (Barry Leiba's message of "Wed, 7 Mar 2012 18:53:37 -0500")
Message-ID: <f5br4x35nbs.fsf@calexico.inf.ed.ac.uk>
User-Agent: Gnus/5.1008 (Gnus v5.10.8) XEmacs/21.4.21 (linux)
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Edinburgh-Scanned: at treacle.ucs.ed.ac.uk with MIMEDefang 2.60, Sophie, Sophos Anti-Virus, Clam AntiVirus
X-Scanned-By: MIMEDefang 2.60 on 129.215.16.102
Cc: "apps-discuss@ietf.org" <apps-discuss@ietf.org>, "oauth@ietf.org" <oauth@ietf.org>, "dr@fb.com" <dr@fb.com>
Subject: Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review of draft-ietf-oauth-v2-23
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Mar 2012 11:45:36 -0000
Barry Leiba <barryleiba@computer.org> writes: > Henry says... >>> No, I appreciate that you want to use registered short names in >>> the protocol, that's just fine. My problem is that you have left >>> users, developers etc. with no way to discover what shortnames >>> have been registered short of a non- trivial and error-prone >>> informal search effort. >>> . . . > > Eran says... >> Not sure I understand what you are asking for, but what would the >> IANA instruction include to support this? > > Yeh, I'm not understanding this either. The spec establishes an > access-token-type registry, and anyone will be able to look in that > registry the same way they look in any other IANA registry, such as > media-types. It looks like Henry is asking for this to use some sort > of type/subtype mechanism, as media-types does, wherein when a new > token type is registered, that registration or subsequent ones can > create subtypes of that token type. No, sorry, not at all about subtyping or anyting like that. Sorry this is proving difficult to communicate! Start again. Consider the situation five years from now, when OAUTH2 is a great success, and there are dozens of entries in its various registries. 1) Suppose you're a developer, setting out to implement OAUTH2. You need to know what access token types, etc. to implement; 2) Or you're a user, wondering what access token types are available, so you can decide which suit your requirements best; 3) Or you're a service provider, and you come up with a new token type and want to check if the name you have in mind is already in use. You have read the spec., and the _only_ concrete thing it tells you about the registers is the name of an email list. So you have to go to the email archives and search for . . . what exactly? Different in the three cases above, and in none of them is it obvious how to know what counts as success. So what I'm asking for is more mechanism, documented in the spec. in terms of what the registry itself will provide, which is, in each case, a URI which will not only resolve to a list of the registered shortnames, but will also support retrieval for any registered short name by appending it. So for example for the access token type registry, the spec. should tell me that retrieving http://www.iana.org/oath2/access-token-types will give me a page listing all the registered access token types, and also http://www.iana.org/oath2/access-token-types/bearer will return the registration details for the bearer type. This will then make all of (1)--(3) easy. Better this time? ht -- Henry S. Thompson, School of Informatics, University of Edinburgh 10 Crichton Street, Edinburgh EH8 9AB, SCOTLAND -- (44) 131 650-4440 Fax: (44) 131 650-4587, e-mail: ht@inf.ed.ac.uk URL: http://www.ltg.ed.ac.uk/~ht/ [mail from me _always_ has a .sig like this -- mail without it is forged spam]
- [OAUTH-WG] FW: Appsdir review of draft-ietf-oauth… Eran Hammer
- Re: [OAUTH-WG] FW: Appsdir review of draft-ietf-o… Justin Richer
- Re: [OAUTH-WG] FW: Appsdir review of draft-ietf-o… Henry S. Thompson
- Re: [OAUTH-WG] FW: Appsdir review of draft-ietf-o… Eran Hammer
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Barry Leiba
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Henry S. Thompson
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Barry Leiba
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Henry S. Thompson
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Barry Leiba
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Henry S. Thompson
- Re: [OAUTH-WG] [apps-discuss] FW: Appsdir review … Derek Atkins