Re: [OAUTH-WG] Draft -09

Eran Hammer-Lahav <eran@hueniverse.com> Sat, 10 July 2010 14:31 UTC

Return-Path: <eran@hueniverse.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 41EF83A69F1 for <oauth@core3.amsl.com>; Sat, 10 Jul 2010 07:31:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1
X-Spam-Level:
X-Spam-Status: No, score=-1 tagged_above=-999 required=5 tests=[AWL=-1.002, BAYES_50=0.001, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q7RR4tlfrCzE for <oauth@core3.amsl.com>; Sat, 10 Jul 2010 07:31:07 -0700 (PDT)
Received: from p3plex1out02.prod.phx3.secureserver.net (p3plex1out02.prod.phx3.secureserver.net [72.167.180.18]) by core3.amsl.com (Postfix) with SMTP id 3470B3A6818 for <oauth@ietf.org>; Sat, 10 Jul 2010 07:31:06 -0700 (PDT)
Received: (qmail 2794 invoked from network); 10 Jul 2010 14:31:11 -0000
Received: from unknown (HELO smtp.ex1.secureserver.net) (72.167.180.19) by p3plex1out02.prod.phx3.secureserver.net with SMTP; 10 Jul 2010 14:31:11 -0000
Received: from P3PW5EX1MB01.EX1.SECURESERVER.NET ([10.6.135.20]) by P3PW5EX1HT001.EX1.SECURESERVER.NET ([72.167.180.19]) with mapi; Sat, 10 Jul 2010 07:31:10 -0700
From: Eran Hammer-Lahav <eran@hueniverse.com>
To: Eran Hammer-Lahav <eran@hueniverse.com>, OAuth WG <oauth@ietf.org>
Date: Sat, 10 Jul 2010 07:31:09 -0700
Thread-Topic: [OAUTH-WG] Draft -09
Thread-Index: AcsXVmRrsO6Hfs/LQgKeY82EBJQ0KwAA86rwAjiVpZo=
Message-ID: <C85DD23D.36F80%eran@hueniverse.com>
In-Reply-To: <90C41DD21FB7C64BB94121FBBC2E72343B3ED4BCCE@P3PW5EX1MB01.EX1.SECURESERVER.NET>
Accept-Language: en-US
Content-Language: en
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_C85DD23D36F80eranhueniversecom_"
MIME-Version: 1.0
Subject: Re: [OAUTH-WG] Draft -09
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 10 Jul 2010 14:31:13 -0000

If you have any more feedback for -09 please submit today. I plan to publish -10 by Monday which will be the last draft for 4 weeks, and hopefully a draft we can declare as stable for implementation. So if there is anything you really want to see changed, today is your last chance for a while.

EHL


On 6/29/10 12:11 AM, "Eran Hammer-Lahav" <eran@hueniverse.com> wrote:

For editorial feedback, I am going to try something new and use SharedCopy.com (no install required).

Try it out at: http://r6.sharedcopy.com/6bnqq8v

If this doesn't work, I'll let people know and cancel it.

EHL



From: oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] On Behalf Of Eran Hammer-Lahav
Sent: Monday, June 28, 2010 11:56 PM
To: OAuth WG (oauth@ietf.org)
Subject: [OAUTH-WG] Draft -09

Draft -09 is now posted. Main changes include:

o  Fixed typos, editorial changes. Thanks to Dick for his useful feedback.
o  Added token expiration example.
o  Added scope parameter to end-user authorization endpoint response and WWW-Authenticate header.
o  Added note about parameters with empty values (same as omitted).
o  Changed parameter values to use '-' instead of '_'.  Parameter names still use '_'.
o  Changed authorization endpoint client type to response type with values: code, token, or both.
o  Complete cleanup of error codes.  Added support for error description and URI.
o  Add initial extensibility support.

Draft -09 represents what I consider to be the first feature complete proposal. While it still needs much work, it has notes for open issues and missing parts. I plan to give people 2 weeks to review and provide extensive feedback, and will post one more draft before the 7/12 cutoff date for the meeting.

My goal is to collect enough feedback to declare the next draft (-10) stable for wider implementation. If you were waiting for a stable draft to study and provide extensive feedback, this is the draft! When giving feedback pretend this is your last chance to making a significant contribution or changes to the core specification.

Please submit feedback by 7/9.

When submitting feedback please start a new thread for each item. Editorial commentary can be collected in one post (and please send to the list, even if it is minor, because I tend to get the same typo correction many times).

Thanks,

EHL