Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id E393F21F86AF for <oauth@ietfa.amsl.com>;
 Fri, 20 Jan 2012 15:22:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.248
X-Spam-Level: 
X-Spam-Status: No, score=-2.248 tagged_above=-999 required=5
 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b3Q2SvTEU5Z0 for
 <oauth@ietfa.amsl.com>; Fri, 20 Jan 2012 15:22:58 -0800 (PST)
Received: from smtprelay01.ispgateway.de (smtprelay01.ispgateway.de
 [80.67.31.24]) by ietfa.amsl.com (Postfix) with ESMTP id 1A34A21F861B for
 <oauth@ietf.org>; Fri, 20 Jan 2012 15:22:57 -0800 (PST)
Received: from [91.2.70.47] (helo=[192.168.71.31]) by
 smtprelay01.ispgateway.de with esmtpsa (TLSv1:RC4-MD5:128) (Exim 4.68)
 (envelope-from <torsten@lodderstedt.net>) id 1RoNl4-00081J-8W;
 Sat, 21 Jan 2012 00:22:55 +0100
References: <90C41DD21FB7C64BB94121FBBC2E723453AAB96537@P3PW5EX1MB01.EX1.SECURESERVER.NET>
User-Agent: K-9 Mail for Android
In-Reply-To: <90C41DD21FB7C64BB94121FBBC2E723453AAB96537@P3PW5EX1MB01.EX1.SECURESERVER.NET>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----WJVYPODLC8YR42PF21QQ7W4O7XG4YH"
From: Torsten Lodderstedt <torsten@lodderstedt.net>
Date: Sat, 21 Jan 2012 00:20:16 +0100
To: Eran Hammer <eran@hueniverse.com>,OAuth WG <oauth@ietf.org>
Message-ID: <b813efbc-5144-4ebb-9211-cb0f39f9da13@email.android.com>
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC1vbmxpbmUuZGU=
Subject: Re: [OAUTH-WG] SHOULD vs MUST for indicating scope on response when
 different from client request
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Jan 2012 23:22:59 -0000

------WJVYPODLC8YR42PF21QQ7W4O7XG4YH
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 8bit

MUST sounds reasonable 



Eran Hammer <eran@hueniverse.com> schrieb:

The current text:

 

   If the issued access token scope

   is different from the one requested by the client, the authorization

   server SHOULD include the "scope" response parameter to inform the

   client of the actual scope granted.

 

Stephen asked why not a MUST. I think it should be MUST. Any disagreement?

 

EHL

 


------WJVYPODLC8YR42PF21QQ7W4O7XG4YH
Content-Type: text/html;
 charset=utf-8
Content-Transfer-Encoding: 8bit

<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:"Courier New";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple>MUST sounds reasonable <br><br><div class="gmail_quote"><br>
<br>
Eran Hammer &lt;eran@hueniverse.com&gt; schrieb:<blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
<div class=WordSection1><p class=MsoNormal>The current text:<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal style='page-break-before:always'><span style='font-size:12.0pt;font-family:"Courier New";color:black'>&nbsp;&nbsp; If the issued access token scope<o:p></o:p></span></p><p class=MsoNormal style='page-break-before:always'><span style='font-size:12.0pt;font-family:"Courier New";color:black'>&nbsp;&nbsp; is different from the one requested by the client, the authorization<o:p></o:p></span></p><p class=MsoNormal style='page-break-before:always'><span style='font-size:12.0pt;font-family:"Courier New";color:black'>&nbsp;&nbsp; server SHOULD include the &quot;scope&quot; response parameter to inform the<o:p></o:p></span></p><p class=MsoNormal style='page-break-before:always'><span style='font-size:12.0pt;font-family:"Courier New";color:black'>&nbsp;&nbsp; client of the actual scope granted.<o:p></o:p></span></p><p class=MsoNormal><o:p>&nbsp;</o:p></p>
 <p
class=MsoNormal>Stephen asked why not a MUST. I think it should be MUST. Any disagreement?<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>EHL<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p></div></blockquote></div></body></html>
------WJVYPODLC8YR42PF21QQ7W4O7XG4YH--

