Re: [OAUTH-WG] Add an option to authorization endpoint to force end-user re-authentication

2010-07-07 Thread Colin Snover
Hi, I just wanted to follow up and see if I could solicit a bit more feedback on this request, since it sounds like the end of the OAuth 2 spec is growing near and I would like to see something added to resolve this problem if at all feasible (or suggestions on how else to deal with it; mayb

Re: [OAUTH-WG] Add an option to authorization endpoint to force end-user re-authentication

2010-06-25 Thread Colin Snover
On 24/06/2010 23:30, Luke Shepard wrote: You're right; this can be an interesting issue. It's very tied up in identity - if you are talking about connecting accounts (like you would with Facebook) then there's a layer missing from OAuth that provides the identity on top of it. At the moment, t

Re: [OAUTH-WG] Add an option to authorization endpoint to force end-user re-authentication

2010-06-24 Thread Luke Shepard
Hey Colin You're right; this can be an interesting issue. It's very tied up in identity - if you are talking about connecting accounts (like you would with Facebook) then there's a layer missing from OAuth that provides the identity on top of it. At the moment, there are a few proposals (for in

[OAUTH-WG] Add an option to authorization endpoint to force end-user re-authentication

2010-06-24 Thread Colin Snover
Hi everyone, I apologise if this has been discussed previously; I searched the list and did not see anything about it. I have been working extensively with OAuth as a client author. A big limitation that we are consistently running into with the way OAuth currently works is that there is no