[OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Martin Ždila
Hello There are some unclear parts in OAuth 2.0 specification. *1.* In 4.3. (B) there is following statement: When making the request, the client authenticates with the authorization server. In 4.3.2 there is following statement: If the client type is confidential or the client was i

Re: [OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Dick Hardt
On Fri, Aug 30, 2013 at 3:41 PM, Martin Ždila wrote: > Hello > > There are some unclear parts in OAuth 2.0 specification. > > *1.* In 4.3. (B) there is following statement: > >When making the request, the client >authenticates with the authorization server. > > > In 4.3.2 there is followin

Re: [OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Todd W Lainhart
Think that there are three different types of clients: confidential; public; and anonymous (my term). Confidential: id and secret; Public: id only; Anonymous: no credentials; You provide the type of credentials that you can, and the protected endpoint will accept or reject based on the operatio