Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-07.txt

2018-08-29 Thread Torsten Lodderstedt
> Am 29.08.2018 um 15:38 schrieb George Fletcher : > > Couldn't the AS issue a token where the audience restriction is a list? This > is true of the id_token spec. Sure, it could. That's certainly better than an unconstraint access token. But the recommendation in the draft is to restrict tok

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-07.txt

2018-08-29 Thread George Fletcher
Couldn't the AS issue a token where the audience restriction is a list? This is true of the id_token spec. On 8/27/18 2:24 PM, Torsten Lodderstedt wrote: Am 27.08..2018 um 11:32 schrieb Vladimir Dzhuvinov mailto:vladi...@connect2id.com>>: Thanks for the update! https://tools.ietf.org/htm