Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Torsten Lodderstedt
Hi Dick, I agree with you, the OAuth standard should offer clear patterns for native apps. All native apps I'm familiar with use the authorization code, which is because of its support for refresh tokens. But the current text of the spec only suggests to use the implict grant flow to impleme

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Richer, Justin P.
Agree with Torsten - having the mention in just that one place doesn't make sense. It should be removed or replicated throughout, but I think we might want a paragraph addressing native apps more deeply in the introduction. We don't want to give the (incorrect) impression that the implicit flow

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Lu, Hui-Lan (Huilan)
+1 Best regards, Huilan LU CONFIDENTIALITY NOTICE: This e-mail and any files attached may contain confidential and proprietary information of Alcatel-Lucent and/or its affiliated entities. Access by the intended recipient only is authorized. Any liability arising from any party acting, or re

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Brian Campbell
I don't disagree with any of that, Dick. But in the absence of any specific solution or recommendation from the WG regarding native apps, I am simply asking that the somewhat misleading text be removed from the framework spec. On Sun, Mar 6, 2011 at 3:12 PM, Dick Hardt wrote: > -1 > > Many sites

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Skylar Woodward
Justin has well stated my view on this. Folks here have explained how the flows can work for (or doesn't prohibit) a native app, but it also seems clear that new readers don't pick up how native apps fit into the flow in a 1st or 2nd pass. So, in short, I agree with Brian's suggestion of (1) r

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Dick Hardt
Brian: I agree with your comments if native apps are not going to be supported in OAuth v2. my -1 is towards dropping native app support, and your suggestion was the easiest thread to comment on. On 2011-03-07, at 7:15 AM, Brian Campbell wrote: > I don't disagree with any of that, Dick. But i

Re: [OAUTH-WG] slightly alternative preamble (was: Re: Draft -12 feedback deadline)

2011-03-07 Thread Eran Hammer-Lahav
I don't have strong views on keeping the reference to native apps, but the spec no longer offers advice on picking a grant type, other than pointing out the importance of being able to keep a secret. The term native app is undefined. What is needed is a separate guide for helping newcomers pick