This draft makes two changes:

 - Removal of the "resource_id" input parameter, whose purpose has been largely 
supplanted by requiring authorization to call the introspection endpoint. I 
also don't know of any implementations that make use of this parameter. If 
there's later consensus on defining more context on the way in, we can easily 
have an extension for that.

 - Re-shuffling of the examples out of an appendix and into the sections that 
they represent; it reads better this way.

 -- Justin

On Dec 23, 2014, at 12:59 PM, <internet-dra...@ietf.org> 
<internet-dra...@ietf.org> wrote:

> 
> A New Internet-Draft is available from the on-line Internet-Drafts 
> directories.
> This draft is a work item of the Web Authorization Protocol Working Group of 
> the IETF.
> 
>        Title           : OAuth 2.0 Token Introspection
>        Author          : Justin Richer
>       Filename        : draft-ietf-oauth-introspection-04.txt
>       Pages           : 13
>       Date            : 2014-12-23
> 
> Abstract:
>   This specification defines a method for a protected resource to query
>   an OAuth 2.0 authorization server to determine the active state of an
>   OAuth 2.0 token and to determine meta-information about this token.
>   OAuth 2.0 deployments can use this method to convey information about
>   the authorization context of the token from the authorization server
>   to the protected resource.
> 
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-oauth-introspection/
> 
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-oauth-introspection-04
> 
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-introspection-04
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to