Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-24.txt

Eran Hammer <eran@hueniverse.com> Thu, 08 March 2012 17:38 UTC

Return-Path: <eran@hueniverse.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 152D821F86AD for <oauth@ietfa.amsl.com>; Thu, 8 Mar 2012 09:38:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.54
X-Spam-Level:
X-Spam-Status: No, score=-2.54 tagged_above=-999 required=5 tests=[AWL=0.059, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V0FP4pAdfK-J for <oauth@ietfa.amsl.com>; Thu, 8 Mar 2012 09:38:34 -0800 (PST)
Received: from p3plex1out01.prod.phx3.secureserver.net (p3plex1out01.prod.phx3.secureserver.net [72.167.180.17]) by ietfa.amsl.com (Postfix) with SMTP id 480D221F86BA for <oauth@ietf.org>; Thu, 8 Mar 2012 09:38:34 -0800 (PST)
Received: (qmail 329 invoked from network); 8 Mar 2012 15:32:11 -0000
Received: from unknown (HELO smtp.ex1.secureserver.net) (72.167.180.19) by p3plex1out01.prod.phx3.secureserver.net with SMTP; 8 Mar 2012 15:32:09 -0000
Received: from P3PW5EX1MB01.EX1.SECURESERVER.NET ([10.6.135.20]) by P3PW5EX1HT001.EX1.SECURESERVER.NET ([72.167.180.19]) with mapi; Thu, 8 Mar 2012 08:24:15 -0700
From: Eran Hammer <eran@hueniverse.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Date: Thu, 08 Mar 2012 08:24:08 -0700
Thread-Topic: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-24.txt
Thread-Index: Acz9FsWLKwJ7ev1pSeiWI93ygu2IZQAKLK1g
Message-ID: <90C41DD21FB7C64BB94121FBBC2E723453AFCD40CD@P3PW5EX1MB01.EX1.SECURESERVER.NET>
References: <20120308054218.5762.28475.idtracker@ietfa.amsl.com> <90C41DD21FB7C64BB94121FBBC2E723453AFCD409D@P3PW5EX1MB01.EX1.SECURESERVER.NET> <4F588AB2.4050003@cs.tcd.ie>
In-Reply-To: <4F588AB2.4050003@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-24.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Mar 2012 17:38:35 -0000

I pushed -25 just in case with this fix.

> -----Original Message-----
> From: Stephen Farrell [mailto:stephen.farrell@cs.tcd.ie]
> Sent: Thursday, March 08, 2012 2:32 AM
> To: Eran Hammer
> Cc: oauth@ietf.org
> Subject: Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-24.txt
> 
> 
> Thanks Eran,
> 
> A question...
> 
> Is this text in 3.1.2.5 correct?
> 
>     If third-party
>     scripts are included, the client MUST NOT ensure that its own scripts
>     (used to extract and remove the credentials from the URI) will
>     execute first.
> 
> "MUST NOT ensure" is a really odd construct. Maybe s/NOT//?
> 
> S
> 
> 
> On 03/08/2012 05:46 AM, Eran Hammer wrote:
> > This draft is ready to go to IESG Review.
> >
> > EH
> >
> >> -----Original Message-----
> >> From: oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] On
> >> Behalf Of internet-drafts@ietf.org
> >> Sent: Wednesday, March 07, 2012 9:42 PM
> >> To: i-d-announce@ietf.org
> >> Cc: oauth@ietf.org
> >> Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-24.txt
> >>
> >>
> >> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> >> This draft is a work item of the Web Authorization Protocol Working
> >> Group of the IETF.
> >>
> >> 	Title           : The OAuth 2.0 Authorization Protocol
> >> 	Author(s)       : Eran Hammer
> >>                            David Recordon
> >>                            Dick Hardt
> >> 	Filename        : draft-ietf-oauth-v2-24.txt
> >> 	Pages           : 66
> >> 	Date            : 2012-03-07
> >>
> >>     The OAuth 2.0 authorization protocol enables a third-party
> >>     application to obtain limited access to an HTTP service, either on
> >>     behalf of a resource owner by orchestrating an approval interaction
> >>     between the resource owner and the HTTP service, or by allowing the
> >>     third-party application to obtain access on its own behalf.  This
> >>     specification replaces and obsoletes the OAuth 1.0 protocol described
> >>     in RFC 5849.
> >>
> >>
> >> A URL for this Internet-Draft is:
> >> http://www.ietf.org/internet-drafts/draft-ietf-oauth-v2-24.txt
> >>
> >> Internet-Drafts are also available by anonymous FTP at:
> >> ftp://ftp.ietf.org/internet-drafts/
> >>
> >> This Internet-Draft can be retrieved at:
> >> ftp://ftp.ietf.org/internet-drafts/draft-ietf-oauth-v2-24.txt
> >>
> >> _______________________________________________
> >> OAuth mailing list
> >> OAuth@ietf.org
> >> https://www.ietf.org/mailman/listinfo/oauth
> > _______________________________________________
> > OAuth mailing list
> > OAuth@ietf.org
> > https://www.ietf.org/mailman/listinfo/oauth
> >