On 4/6/10 5:24 PM, "Evan Gilbert" <uid...@google.com> wrote:

> Proposal:
> In 2.4.1 & 2.4.2, add the following OPTIONAL parameter
> username
>   The resource owner's username. The authorization server MUST only send back
> refresh tokens or access tokens for the user identified by username.

What are the security implications? How can the client know that the token
it got is really for that user?

EHL

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to