Re: [oauth] oauth_callback parameter not sent to getsatisfaction

2010-04-26 Thread k42b3
hi, However GetSatisfaction requires that oauth_callback=http://mysite.com/myresource be sent along with the authorization url As you mentioned the callback url must be send when you obtain the "Temporary Credentials". You can set the callback to "oob" but then you have to provide the url in

Re: [oauth] oauth_callback parameter not sent to getsatisfaction

2010-04-26 Thread Lukas Rosenstock
Hi! Just to clarify: The protocol knows two ways for sending the OAuth callback, one is along with the request token; and the other is by attaching it to the URL. The former (1.0a) is recommended and was introduced after security issues had been known about the latter (1.0). Regards, Lukas 2010/

Re: [oauth] oauth_callback parameter not sent to getsatisfaction

2010-04-26 Thread Vasu Srinivasan
Ok, now I realize that there are two ways of sending OAuth callback. Thanks for the help! On Mon, Apr 26, 2010 at 5:08 AM, Lukas Rosenstock wrote: > Hi! > Just to clarify: The protocol knows two ways for sending the OAuth > callback, one is along with the request token; and the other is by attac

[oauth] Found two small mistakes in draft-hammer-oauth2-00.txt document

2010-04-26 Thread KiNgMaR
Hey, while OAuth 2.0 seems very nice and very well thought through overall, I couldn't help but notice two small mistakes in the draft: a) In section 5.3, it says ... with a matchin "hmac-sha256" secret by using the "token_type" parameter when requesting an access token. and it should say "s

Re: [oauth] Found two small mistakes in draft-hammer-oauth2-00.txt document

2010-04-26 Thread Peter Saint-Andre
On 4/26/10 9:16 AM, KiNgMaR wrote: > while OAuth 2.0 seems very nice and very well thought through overall, > I couldn't help but notice two small mistakes in the draft: Please send feedback about the Internet-Draft to the IETF list: https://www.ietf.org/mailman/listinfo/oauth /psa smime.p7s