[OAUTH-WG] SHOULD vs MUST for indicating scope on response when different from client request

Eran Hammer <eran@hueniverse.com> Fri, 20 January 2012 23:19 UTC

The current text:

   If the issued access token scope
   is different from the one requested by the client, the authorization
   server SHOULD include the "scope" response parameter to inform the
   client of the actual scope granted.

Stephen asked why not a MUST. I think it should be MUST. Any disagreement?