On Mon, Apr 4, 2011 at 12:09 PM, Kris Selden <kris.sel...@gmail.com> wrote: > I completely agree with you regarding not being able to authenticate a native > client. > > The problem with web flow is the user experience is bad for a native app. > Why does this matter? Because of competition – if competitors use a user > friendly but less secure method and the end user does not know it is bad for > them, then because of market forces you have to do the same.
User experience should be identical for both User-Agent and Web Server flows. With User-Agent typically you get only a short lived access token, so for more cases this will not work at all for native apps. Marius _______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth