Re: [OAUTH-WG] Shepherd Review of draft-ietf-oauth-security-topics-23

2024-01-04 Thread Axel.Nennker
Sorry, for me an all-capitalized MAY is not a recommendation to use PKCE MAY This word, or the adjective "OPTIONAL", mean that an item is truly optional. One vendor may choose to include the item because a particular marketplace requires it or because the vendor feels that it enhances

Re: [OAUTH-WG] Draft for “web_message” Response Mode - Asking For Feedback

2024-01-04 Thread Filip Skokan
Hello Karsten, Can you summarize in what ways is your draft compatible with draft-sakimura-oauth-wmrm-00? Which of the described modes in Nat's document does it cover? There are existing implementations (both partial and full) of draft-sakimura-oauth-wmrm-00 so if your draft is not compatible I w

Re: [OAUTH-WG] Draft for “web_message” Response Mode - Asking For Feedback

2024-01-04 Thread Karsten Meyer zu Selhausen | Hackmanit
Hi all, we would like to ask again for feedback on our draft for the "web_message" response mode: *https://datatracker.ietf.org/doc/draft-meyerzuselha-oauth-web-message-response-mode/ * We think it would be very helpful for implementers and developers to specify a secure standard for a postM

[OAUTH-WG] OAuth Security Workshop 2024 | April 10-12 | Rome, Italy

2024-01-04 Thread Daniel Fett
Hi all, This year's OAuth Security Workshop will be hosted by Fondazione Bruno Kessler and will take place in Rome/Italy, April 10-12. Like last year, there are two deadlines for the Call for Sessions, February 11 and March 10, in order to provide early feedback for those that need confirmed