Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-browser-based-apps-16.txt

2024-02-16 Thread Aaron Parecki
Hi all, Thanks to Filip Skokan for his thorough review of the OAuth for Browser-Based Apps BCP. I've incorporated his changes as well as a few other editorial fixes from Louis Jannett and published Draft 16. You can view the latest version here: https://www.ietf.org/archive/id/draft-ietf-oauth-br

[OAUTH-WG] I-D Action: draft-ietf-oauth-browser-based-apps-16.txt

2024-02-16 Thread internet-drafts
Internet-Draft draft-ietf-oauth-browser-based-apps-16.txt is now available. It is a work item of the Web Authorization Protocol (OAUTH) WG of the IETF. Title: OAuth 2.0 for Browser-Based Apps Authors: Aaron Parecki David Waite Philippe De Ryck Name:draft-ietf

Re: [OAUTH-WG] OAuth browser based apps with first-party same-domain apps

2024-02-16 Thread Aaron Parecki
Hi Kai, This sounds similar to an approach described in this draft, although never actually implemented as far as I know: https://www.ietf.org/archive/id/draft-hanson-oauth-cookie-response-mode-00.html The main difference is the hanson draft does a redirect to the authorization endpoint, but the

Re: [OAUTH-WG] FW: Call for consensus on SPICE charter

2024-02-16 Thread Orie Steele
Hey Tony, On Thu, Feb 15, 2024 at 1:36 PM wrote: > 1) Do you support the charter text? Or do you have objections or blocking > concerns (please describe what they might be and how you would propose > addressing the concern)? > > Not sure I support at this point, I understand the need for an > ar