Re: [OAUTH-WG] Cross-Device Flows: Security Best Current Practice Review

2024-04-23 Thread Roy Williams (E+P)
Thank you Pieter. From: Pieter Kasselman Sent: Tuesday, April 23, 2024 6:43 AM To: Roy Williams (E+P) ; oauth@ietf.org Subject: RE: Cross-Device Flows: Security Best Current Practice Review Thanks Roy, thanks for the review and feedback, much apprecioated. I have opened two issues to add

Re: [OAUTH-WG] Cross-Device Flows: Security Best Current Practice Review

2024-04-23 Thread Pieter Kasselman
Thanks Roy, thanks for the review and feedback, much apprecioated. I have opened two issues to add clarification and provide additional guidance to implementers. 1. Highlight edge cases of geolocation based on IP Address * Issue #123 * oauth-wg/oauth-cross-device-security

[OAUTH-WG] Cross-Device Flows: Security Best Current Practice Review

2024-04-22 Thread Roy Williams (E+P)
I had promised at the 119 meeting that I would review this document and give feedback. I have completed that document and other than two potential clarification points, I found it to be helpful. The following two areas could be slightly improved: 1. At the end of section (5) there is a