Re: [OAUTH-WG] OAuth for Browser-Based Apps Draft 12

Thomas Broyer <t.broyer@gmail.com> Wed, 07 December 2022 08:51 UTC

Return-Path: <t.broyer@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B90BC14CE2F for <oauth@ietfa.amsl.com>; Wed, 7 Dec 2022 00:51:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P2RcuR-D5Q9X for <oauth@ietfa.amsl.com>; Wed, 7 Dec 2022 00:51:55 -0800 (PST)
Received: from mail-vs1-xe33.google.com (mail-vs1-xe33.google.com [IPv6:2607:f8b0:4864:20::e33]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DCCFCC14F74F for <oauth@ietf.org>; Wed, 7 Dec 2022 00:51:55 -0800 (PST)
Received: by mail-vs1-xe33.google.com with SMTP id i2so16621171vsc.1 for <oauth@ietf.org>; Wed, 07 Dec 2022 00:51:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=GHsiYHapGOn43UAZ6qK5jDg+LxV7PcUjp3NViUdKvYg=; b=lMLQuTzz5y2a9TMEswVuO/2LXvrXq3UiMpjQKyo/D8KidCIjUB6/BSZ/ujiAPn27J+ ty3hRxRfkLFyzIH2PYTaAa3kIE0WiCKdueqqbC25nYpxFLQysFAW41CWsG0A0hgtKkHv lv++Q4dr530n1J3uPLreR6huCMpcMrUxGHrj8fZdGOGGjHJ1PZyR0kJ83s5zQCDH839i WorMHjOspJjqm1TQk4FMtGHOrYx1C18KhBd4meepy4fBkLt7YL8qAzVAkgQaa1qZAK0+ +3zS12zTZk5eB4p/M+5n8tSmtQWlF0CbfA/c3m094EqCGVO9e8JH8EQAiAiX6vTG5MJM 9eaA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=GHsiYHapGOn43UAZ6qK5jDg+LxV7PcUjp3NViUdKvYg=; b=fkAoEu9PQXbd68q8jTvVJKN+bdZBn+Fd7r8XjnsLgs6sLoOQyUppAF73cODaK4UYEw WP1TgoHFGe26Vaber6qs+RcWGsZRWtc3B0w7Gki/r6hCcCWvxrLL1+LJxaiezRgC/aLl 8ovwd+Z3l9KrNPKuleg4xNr+vKbTELIchfaXzxW6ZPcPLWuMix2ZVeqrceHtr4FYHYeC tdOjFdCs49mQOhV6X4vNO2UI+tlrPSc58ReyoiA5QHzSonNoI4z37k9Jdv5lSp46BnWm EVWya9s+cY9gf0uAKMN31/IaF+6xdkPjeTSkG210iUIeBZkfYDidqAdcdmUF/ig1fYJf /hNQ==
X-Gm-Message-State: ANoB5pmEbLQATTIpm0ZUE/m9gia9ksceswhm/J/qGJvGW9LQtVls0nL8 tOfOtVTF08cVxmvpHMKq19d0ouC1Uwa+rU+tBTIR/LlM
X-Google-Smtp-Source: AA0mqf5Hiizc6xgphZ0P7N/vpIREInTtodqKpK2Q5L/tKq4R6t9yqOKGNgdVc324YcU6wTRXGQdwfa54CtSm5YEC1Sc=
X-Received: by 2002:a67:fdc6:0:b0:3b0:cb24:21b6 with SMTP id l6-20020a67fdc6000000b003b0cb2421b6mr17712395vsq.52.1670403114827; Wed, 07 Dec 2022 00:51:54 -0800 (PST)
MIME-Version: 1.0
References: <167036996045.32057.8617864278204705226@ietfa.amsl.com> <CAGBSGjosYKJXVaJSN9B5ZFFB4B9h0wogQ9auQN4wm3dSqkZe_g@mail.gmail.com>
In-Reply-To: <CAGBSGjosYKJXVaJSN9B5ZFFB4B9h0wogQ9auQN4wm3dSqkZe_g@mail.gmail.com>
From: Thomas Broyer <t.broyer@gmail.com>
Date: Wed, 07 Dec 2022 09:51:43 +0100
Message-ID: <CAEayHEMRwPiexS79Gw9_Ew=_dL0TmBA7dnZgBum4XVq_94nXtA@mail.gmail.com>
To: Aaron Parecki <aaron=40parecki.com@dmarc.ietf.org>
Cc: OAuth WG <oauth@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000004a822c05ef390823"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Rd1EG9bXiZOK5gTc99Jt7xY0iL8>
Subject: Re: [OAUTH-WG] OAuth for Browser-Based Apps Draft 12
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Dec 2022 08:51:59 -0000

On Wed, Dec 7, 2022 at 1:07 AM Aaron Parecki <aaron=
40parecki.com@dmarc.ietf.org> wrote:

> Hi all,
>
> I just published a revised version of OAuth for Browser-Based Apps based
> on the feedback and discussion at IETF 115 London!
>
> https://www.ietf.org/archive/id/draft-ietf-oauth-browser-based-apps-12.html
>
> The primary changes are:
>
> * Rephrased the architecture patterns to focus on token acquisition
>

Terminology-wise, the phrasing "code executed in the DOM" is not correct:
the DOM is an API for manipulating the document. This should rather be
"code executed in a browsing context" or possibly "code executed in a
document context" (or just "in a document"?), as opposed to a "worker
context" or service worker.

Anyway, thanks for that work. I'm only using the drafts as reference in
architecture discussions and am looking forward to this turning into an RFC.
-- 
Thomas Broyer
/tɔ.ma.bʁwa.je/ <http://xn--nna.ma.xn--bwa-xxb.je/>