-12 3.1.1:

   The redirection URI MUST be an absolute URI and MAY include a query
   component, which MUST be retained by the authorization server when
   adding additional query parameters.

'oob' is not an absolute URI.

EHL

> -----Original Message-----
> From: Marius Scurtescu [mailto:mscurte...@google.com]
> Sent: Friday, January 28, 2011 10:07 AM
> To: Eran Hammer-Lahav
> Cc: Skylar Woodward; OAuth WG
> Subject: Re: [OAUTH-WG] Native Client Extension
> 
> On Fri, Jan 28, 2011 at 8:21 AM, Eran Hammer-Lahav
> <e...@hueniverse.com> wrote:
> > Why not:
> >
> > urn:ietf:wg:oauth:2.0:oob
> >
> > Can you can add more flavors for different ways of floating the token/code
> up to the application. This requires no changes at all to -12 to allow this
> special case.
> 
> Using the simpler "oob" does require changes to the core spec? Why?
> 
> Marius
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to