Hi, I have been reviewing the last RAR draft (https://datatracker.ietf.org/doc/html/draft-ietf-oauth-rar-23) and I was expecting to find some references about how to use the “WWW-Authenticate” Response Header Field defined in RFC6750 (https://datatracker.ietf.org/doc/html/rfc6750#section-3) in this document.
I think that RAR is a great idea for complex authorization where a “scope” is not enough to describe what you want to authorize, in OAuth 2.0 there exist a way for a protected resource to indicate what “scopes” are need it to consider the request “authorized”, should not be an standard way to do the same for rich authorization request? Best regards. Emails aren't always secure, and they may be intercepted or changed after they've been sent. Santander doesn't accept liability if this happens. If you think someone may have interfered with this email, please get in touch with the sender another way. This message doesn't create or change any contract. Santander doesn't accept responsibility for damage caused by any viruses contained in this email or its attachments. Emails may be monitored. If you've received this email by mistake, please let the sender know at once that it's gone to the wrong person and then destroy it without copying, using, or telling anyone about its contents. Santander UK plc. Registered Office: 2 Triton Square, Regent's Place, London, NW1 3AN, United Kingdom. Registered Number 2294747. Registered in England and Wales. https://www.santander.co.uk. Telephone 0800 389 7000. Calls may be recorded or monitored. Authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority. Our Financial Services Register number is 106054. You can check this on the Financial Services Register by visiting the FCA’s website https://www.fca.org.uk/register. Santander and the flame logo are registered trademarks. Ref:[PDB#1-4B]
_______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth