Re: [GNAP] [Txauth] Revisiting the photo sharing example (a driving use case for the creation of OAuth)

Dave Tonge <> Fri, 14 August 2020 01:39 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 8400A3A0BE6 for <>; Thu, 13 Aug 2020 18:39:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id iIZ8GtLC0ui2 for <>; Thu, 13 Aug 2020 18:39:20 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:4864:20::1029]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 268BE3A0BE3 for <>; Thu, 13 Aug 2020 18:39:20 -0700 (PDT)
Received: by with SMTP id t6so3649893pjr.0 for <>; Thu, 13 Aug 2020 18:39:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=nYkdryqDvrBR0s4rAoCm4mnMVYuf7mjmywrZX77hKR8=; b=LLMh36rJXwwTz6fbP8k7DGE06+cXWnE83DpivrKShSWsN6ZjuBSunmUpxKETu69wZR g5jzfWPhaDSVlMr5CghmJBE+jBINIrkHB6zb5XCab8N78f2hnjFUPY9Nc8ff2pEM8KzV EQe4vNyJdESJOrRBe0TttHAjJSV7Qu3qgI5d4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=nYkdryqDvrBR0s4rAoCm4mnMVYuf7mjmywrZX77hKR8=; b=YBKjNTeNzS8iVF/GpTbCIjDNtvBy5Vy8Pzpyd4gd8wl+exE3l4b0bu1My6wRFnuDIp YxHOv1FUzKScODmQOq/fTvNyB8FAIwFVvLVmoXuHmBE9ePpFqGHBZixvKGaJUX8vT/qJ l7hO06QdQDE0MlC4NUjxBFNXOeoT6xh0qyPkffk8WFFtg7rNGbce+ArsBYjrdEnJtkZa IMdNDmc2pMnr7FpRFP7TSm61APVfzTuH48LWGZXgNyXBzozAiHtJa3tXzbSfcKU+guuQ 8NGdK0VcMlHIMxNjJYZQZxqCQmaHgPvzxg4ujUBPhMJAGwrrIsO3j7Xqkjb6S39DjpjZ puOg==
X-Gm-Message-State: AOAM533Vb2pc5luUHfkLzMKKGqX7nkFjUzfzjUS2yNU+y8Qmm72TTogd Zl9NGrAbDi1amMRMxTub102qSULK2DFV8rmicSx8Gep3guB4Me/YowMhrkDIZDzxP2xiQ2tU32Y HtGYcOKhnI2ksdB0=
X-Google-Smtp-Source: ABdhPJwEdp5SNyY5JBEZSDQ/ISnmLbW5kFDCCyEqiwMpb/mmRBBr8KJTAAT6epZhl/nDXiIhs+8RyJMaR24HaDAQ+Yc=
X-Received: by 2002:a17:90a:1a42:: with SMTP id 2mr367802pjl.16.1597369159428; Thu, 13 Aug 2020 18:39:19 -0700 (PDT)
MIME-Version: 1.0
References: <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
From: Dave Tonge <>
Date: Fri, 14 Aug 2020 03:39:08 +0200
Message-ID: <>
To: Dick Hardt <>
Cc: Fabien Imbault <>, Francis Pouatcha <>, Denis <>, "" <>, Justin Richer <>, Benjamin Kaduk <>
Content-Type: multipart/alternative; boundary="00000000000052ccf705accc7d2f"
Archived-At: <>
Subject: Re: [GNAP] [Txauth] Revisiting the photo sharing example (a driving use case for the creation of OAuth)
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 14 Aug 2020 01:39:22 -0000

> I agree with clearly separating the GS interaction with the Client from
the interaction with the User.

> I'm having a hard time viewing those as two different roles. They are two
different interactions. Just as the client interaction with the AS is
different from the client interaction with the GS.

I also struggle to see these as different roles - they seem to be
fundamentally linked,
However what I think does need to be taken into consideration is that there
may be multiple Grant Servers involved in a user flow (I've added a new use
case to describe some of these flows:


Moneyhub Enterprise is a trading style of Moneyhub Financial Technology 
Limited which is authorised and regulated by the Financial Conduct 
Authority ("FCA"). Moneyhub Financial Technology is entered on the 
Financial Services Register (FRN 809360) at 
<>. Moneyhub Financial Technology is registered 
in England & Wales, company registration number 06909772. Moneyhub 
Financial Technology Limited 2020 © Moneyhub Enterprise, Regus Building, 
Temple Quay, 1 Friary, Bristol, BS1 6EA. 

DISCLAIMER: This email 
(including any attachments) is subject to copyright, and the information in 
it is confidential. Use of this email or of any information in it other 
than by the addressee is unauthorised and unlawful. Whilst reasonable 
efforts are made to ensure that any attachments are virus-free, it is the 
recipient's sole responsibility to scan all attachments for viruses. All 
calls and emails to and from this company may be monitored and recorded for 
legitimate purposes relating to this company's business. Any opinions 
expressed in this email (or in any attachments) are those of the author and 
do not necessarily represent the opinions of Moneyhub Financial Technology 
Limited or of any other group company.