Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Doug Tangren
>> EHL > >> > >> > -Original Message- > >> > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On > Behalf > >> > Of Marius Scurtescu > >> > Sent: Monday, July 11, 2011 3:15 PM > >> > To: Doug Tangr

Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Ian McKellar
om: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf >> > Of Marius Scurtescu >> > Sent: Monday, July 11, 2011 3:15 PM >> > To: Doug Tangren >> > Cc: oauth@ietf.org >> > Subject: Re: [OAUTH-WG] best practices for storing access token

Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Larry Suto
. > > EHL > > > -Original Message- > > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf > > Of Marius Scurtescu > > Sent: Monday, July 11, 2011 3:15 PM > > To: Doug Tangren > > Cc: oauth@ietf.org > > Subject: Re: [OAUTH-WG] best p

Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Ian McKellar
:15 PM >> To: Doug Tangren >> Cc: oauth@ietf.org >> Subject: Re: [OAUTH-WG] best practices for storing access token for implicit >> clients >> >> On Thu, Jun 30, 2011 at 12:45 PM, Doug Tangren >> wrote: >> > What is the current recommended practice of st

Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Eran Hammer-Lahav
Sent: Monday, July 11, 2011 3:15 PM > To: Doug Tangren > Cc: oauth@ietf.org > Subject: Re: [OAUTH-WG] best practices for storing access token for implicit > clients > > On Thu, Jun 30, 2011 at 12:45 PM, Doug Tangren > wrote: > > What is the current recommended pract

Re: [OAUTH-WG] best practices for storing access token for implicit clients

2011-07-11 Thread Marius Scurtescu
On Thu, Jun 30, 2011 at 12:45 PM, Doug Tangren wrote: > What is the current recommended practice of storing an implicit client's > access_tokens? LocalStorage, im mem and re-request auth on every browser > refresh? Both sound reasonable. I think most important is how NOT to store it, in a cookie.

[OAUTH-WG] best practices for storing access token for implicit clients

2011-06-30 Thread Doug Tangren
What is the current recommended practice of storing an implicit client's access_tokens? LocalStorage, im mem and re-request auth on every browser refresh? -Doug Tangren http://lessis.me ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/l

[OAUTH-WG] best practices for storing access token for implicit clients

2011-06-30 Thread Doug Tangren
What is the current recommended practice of storing an implicit client's access_tokens? LocalStorage, im mem and re-request auth on every browser refresh? -Doug Tangren http://lessis.me ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/l