Re: [OAUTH-WG] Issue: add refresh token as optional in all access token requests

Mark Mcgloin <mark.mcgloin@ie.ibm.com> Fri, 16 April 2010 16:27 UTC

Return-Path: <mark.mcgloin@ie.ibm.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 50D5828C149; Fri, 16 Apr 2010 09:27:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.949
X-Spam-Level:
X-Spam-Status: No, score=-2.949 tagged_above=-999 required=5 tests=[AWL=-0.350, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id obtW0CJT7VJv; Fri, 16 Apr 2010 09:27:33 -0700 (PDT)
Received: from mtagate7.uk.ibm.com (mtagate7.uk.ibm.com [194.196.100.167]) by core3.amsl.com (Postfix) with ESMTP id D643F28C187; Fri, 16 Apr 2010 09:25:15 -0700 (PDT)
Received: from d06nrmr1806.portsmouth.uk.ibm.com (d06nrmr1806.portsmouth.uk.ibm.com [9.149.39.193]) by mtagate7.uk.ibm.com (8.13.1/8.13.1) with ESMTP id o3GGP7ch009483; Fri, 16 Apr 2010 16:25:07 GMT
Received: from d06av02.portsmouth.uk.ibm.com (d06av02.portsmouth.uk.ibm.com [9.149.37.228]) by d06nrmr1806.portsmouth.uk.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id o3GGOxZP1302684; Fri, 16 Apr 2010 17:25:07 +0100
Received: from d06av02.portsmouth.uk.ibm.com (loopback [127.0.0.1]) by d06av02.portsmouth.uk.ibm.com (8.12.11.20060308/8.13.3) with ESMTP id o3GGOwaW016734; Fri, 16 Apr 2010 17:24:58 +0100
Received: from d06ml901.portsmouth.uk.ibm.com (d06ml901.portsmouth.uk.ibm.com [9.149.39.138]) by d06av02.portsmouth.uk.ibm.com (8.12.11.20060308/8.12.11) with ESMTP id o3GGOw8u016727; Fri, 16 Apr 2010 17:24:58 +0100
In-Reply-To: <F74CD1E6-8B47-4F42-8E08-6F31CB6174B5@bbn.com>
To: OAuth WG <oauth@ietf.org>, oauth-bounces@ietf.org
X-Mailer: Lotus Notes Release 7.0 HF400 February 20, 2008
Message-ID: <OFD5F73A7B.828EC618-ON80257707.0059D87C-80257707.005A2B00@ie.ibm.com>
From: Mark Mcgloin <mark.mcgloin@ie.ibm.com>
Date: Fri, 16 Apr 2010 17:24:53 +0100
X-MIMETrack: Serialize by Router on D06ML901/06/M/IBM(Release 8.0.2FP2|June 22, 2009) at 16/04/2010 17:24:57
MIME-Version: 1.0
Content-type: text/plain; charset="US-ASCII"
Subject: Re: [OAUTH-WG] Issue: add refresh token as optional in all access token requests
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Apr 2010 16:27:34 -0000

+1 to this

Mark McGloin

>On 16/04/2010 17:08, Richard Barnes <rbarnes@bbn.com>  wrote:

>Sure, this seems sensible, especially with the *optional* part.



>On Apr 15, 2010, at 3:22 PM, David Recordon wrote:

>> +1, remember discussing this a week or so ago on the list
>>
>>> On Thu, Apr 15, 2010 at 12:12 PM, Eran Hammer-Lahav
<eran@hueniverse.com
>> > wrote:
>> Proposal: Keep bearer tokens as the default first-issued credential
>> and add
>> an optional refresh token everywhere.
>>
>> EHL