Re: [OAUTH-WG] Query on RFC 7009

2019-07-22 Thread Torsten Lodderstedt
Hi James, > On 11. Jun 2019, at 17:53, James Howe wrote: > > Unless I'm mistaken, RFC 7009 doesn't specify the error response when the > request is from a different client to the issuer. > > Section 2.1: >> If this validation fails, the request is refused and the client is informed >> of the

[OAUTH-WG] Query on RFC 7009

2019-06-11 Thread James Howe
Unless I'm mistaken, RFC 7009 doesn't specify the error response when the request is from a different client to the issuer. Section 2.1: > If this validation fails, the request is refused and the client is informed > of the error by the authorization server as described below. The only relevant