(restarting discussion from
        
http://groups.google.com/group/oauth-ietf-wg/browse_thread/thread/8aeb31817ead4c2a/f19773643e0a8ba3?pli=1
 with matching subject)

Given the practice that the authorization endpoint and the redirect_uri can 
contain URI query parameters, then differentiating between application specific 
query parameters and OAuth protocol parameters by prefixing the OAuth 
parameters with oauth_ would seem a useful way to minimize conflicts.

Since calls to the token endpoint use POST, there can not be any confusion 
between the parameters in the body of the message and URI query parameters

Note this has nothing to do with differentiating between protocol extension 
parameters and core OAuth parameters.

-- Dick
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to