Re: [OAUTH-WG] OAuth 2.0 Token Exchange: An STS for the REST of Us -03 announcement redux

2016-01-06 Thread Vladimir Dzhuvinov
Hi Brian, 1. The introduction is excellent! Previous versions were lacking in this regard and readers were left guessing or unaware about key aspects of the spec and how to make use of it. Good work! 2.1. Are clients allowed to mix or include both "resource" and "audience" request parameters at t

[OAUTH-WG] Advertise PKCE support in OAuth 2.0 Discovery (draft-jones-oauth-discovery-00)

2016-01-06 Thread Vladimir Dzhuvinov
I just noticed PKCE support is missing from the discovery metadata. Is it a good idea to add it? Cheers, Vladimir -- Vladimir Dzhuvinov smime.p7s Description: S/MIME Cryptographic Signature ___ OAuth mailing list OAuth@ietf.org https://www.ietf.o

Re: [OAUTH-WG] Advertise PKCE support in OAuth 2.0 Discovery (draft-jones-oauth-discovery-00)

2016-01-06 Thread John Bradley
Good point. Now that PKCE is a RFC we should add it to discovery. John B. > On Jan 6, 2016, at 9:29 AM, Vladimir Dzhuvinov > wrote: > > I just noticed PKCE support is missing from the discovery metadata. > > Is it a good idea to add it? > > Cheers, > > Vladimir > > -- > Vladimir Dzhuvinov

Re: [OAUTH-WG] Advertise PKCE support in OAuth 2.0 Discovery (draft-jones-oauth-discovery-00)

2016-01-06 Thread Torsten Lodderstedt
+1 Am 06.01.2016 um 18:25 schrieb William Denniss: +1 On Wed, Jan 6, 2016 at 6:40 AM, John Bradley > wrote: Good point. Now that PKCE is a RFC we should add it to discovery. John B. > On Jan 6, 2016, at 9:29 AM, Vladimir Dzhuvinov mailto:vladi...@co