Re: [OAUTH-WG] draft-parecki-oauth-browser-based-apps and response_type/fragment

Aaron Parecki <aaron@parecki.com> Sat, 08 December 2018 18:23 UTC

Return-Path: <aaron@parecki.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AA01D130E69 for <oauth@ietfa.amsl.com>; Sat, 8 Dec 2018 10:23:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.358
X-Spam-Level:
X-Spam-Status: No, score=-3.358 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-1.459, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=parecki-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sfZHX4ak4L1r for <oauth@ietfa.amsl.com>; Sat, 8 Dec 2018 10:23:41 -0800 (PST)
Received: from mail-it1-x129.google.com (mail-it1-x129.google.com [IPv6:2607:f8b0:4864:20::129]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 792F7130E64 for <oauth@ietf.org>; Sat, 8 Dec 2018 10:23:41 -0800 (PST)
Received: by mail-it1-x129.google.com with SMTP id x124so4246263itd.1 for <oauth@ietf.org>; Sat, 08 Dec 2018 10:23:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=parecki-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=djlg7tpQk6H8PCg0mEZiCVKDmQeME0gZ0R9PXOR1cSI=; b=nrYf+vzIMNapXC5JMXv+7bvop5oABTg2iQXHvvnXLM42/SEOxJPUszLo1QqWkFxIPc /0Y4RmHqQviYkSzpHmshIVHwGkVg6hDA5c1G4PaqkxQWvNg9cdM7g8/fe5kzcNymbszU s3luRAXSjjY88IwocddSE5e8oviCtZPCqg8dEAO05ZeSLRkDlRxITC1XP0HnzobvDW4f RWlV8t9/tQHYhxpPpW9/+iZa1MN8gkqBDHKChp/cfOfw+s9KJskNYHsGIUL1me2lMGv+ ohI3PxkTfaL8XQqBEGvuEKGlNYKy6ywcB/WRw60S9KcuZrcjHpYUD8tpg9gXNiLbKiLj vO/g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=djlg7tpQk6H8PCg0mEZiCVKDmQeME0gZ0R9PXOR1cSI=; b=fcDEAbyixb8h0tvrXG1zudByD8B57DI5kVFprFMo/pHtSKMm+35kt2Aaotrj1xCxZQ 7wq+GR/fQQ2k6vI6TIbCCoFErLLuk9gVe1MXiYCPVeyG5Zak6omR0NX7Cu8QToPd/n38 J5BpX8ctXs166vNEeWe0LTiMRUEyG53sraYZGnUEQu+p17p72q3PxuTaoSwxEDTKXMWh 8L6M/I2TsoKhQhNNvC26SCpTQrNFRscPgBJpDjNW8Dl+DwoWywUuccmv8bj34WH1zHNB aIgjzvWJXu0M2s4xrPUhlG80uBPgnTNH4wuCOYEm8gyvuo9LEi/A714pmYTECNZb0cZ5 gvCg==
X-Gm-Message-State: AA+aEWaxwvJwNx8bv5qw9eLLyMpfEt7euetihT4yvbWwH/AGM1+4nF7X ILAzRWNzPZfi4e/hvbFIAVyAjp+JquU=
X-Google-Smtp-Source: AFSGD/XzcStB9SjpI6euRHFcjIKjUT1/Ua/XM06vR8xN3fcpW+1ieiwgA5Cmzda/TiOLfPGj5ZEKcw==
X-Received: by 2002:a24:3dd5:: with SMTP id n204mr6583074itn.104.1544293420530; Sat, 08 Dec 2018 10:23:40 -0800 (PST)
Received: from mail-it1-f172.google.com (mail-it1-f172.google.com. [209.85.166.172]) by smtp.gmail.com with ESMTPSA id 196sm3524766itu.33.2018.12.08.10.23.39 for <oauth@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 08 Dec 2018 10:23:39 -0800 (PST)
Received: by mail-it1-f172.google.com with SMTP id x19so11806592itl.1 for <oauth@ietf.org>; Sat, 08 Dec 2018 10:23:39 -0800 (PST)
X-Received: by 2002:a02:8904:: with SMTP id o4mr5958298jaj.35.1544293419402; Sat, 08 Dec 2018 10:23:39 -0800 (PST)
MIME-Version: 1.0
References: <6d88c55a-a300-47ff-af77-8fdb7dcfbc25@getmailbird.com>
In-Reply-To: <6d88c55a-a300-47ff-af77-8fdb7dcfbc25@getmailbird.com>
From: Aaron Parecki <aaron@parecki.com>
Date: Sat, 08 Dec 2018 10:23:27 -0800
X-Gmail-Original-Message-ID: <CAGBSGjrj95i97mVDJq7jDA0DsLH-NasiH+E0nqc+6XjL-mnt4Q@mail.gmail.com>
Message-ID: <CAGBSGjrj95i97mVDJq7jDA0DsLH-NasiH+E0nqc+6XjL-mnt4Q@mail.gmail.com>
To: Brock Allen <brockallen@gmail.com>
Cc: OAuth WG <oauth@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b14f3d057c86d444"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/TIigqDIICWN3yMV1KGJqDpiDaEc>
Subject: Re: [OAUTH-WG] draft-parecki-oauth-browser-based-apps and response_type/fragment
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 08 Dec 2018 18:23:44 -0000

What would be the benefit of using this response type? Are you aware of any
OAuth (not OIDC) clients that do this today?

- Aaron


On Sat, Dec 8, 2018 at 7:29 AM Brock Allen <brockallen@gmail.com> wrote:

> Should the BCP suggest using OIDC's response_type=fragment as the
> mechanism for returning the code from the AS? Or simply suggest using the
> fragment component of the redirect_uri for the code, without a
> response_type parameter (IOW don't allow it to be dynamic)?
>
> -Brock
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>