Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-24 Thread Igor Faynberg
Thanks, Eve! Igor On 10/23/2012 7:36 PM, Eve Maler wrote: Hi Igor-- If you mean enabling (um) Grandma Goldie to delegate child pickup duties to Tom the Taxi Driver after having been herself delegated to pick up the child by Peter Parent, then -- as long as we're focusing on policy-based claim

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-23 Thread Eve Maler
Hi Igor-- If you mean enabling (um) Grandma Goldie to delegate child pickup duties to Tom the Taxi Driver after having been herself delegated to pick up the child by Peter Parent, then -- as long as we're focusing on policy-based claims-tested authorization for requesting party access, then UMA

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-23 Thread Eve Maler
Sorry for the delay. Here's what I was thinking about: https://dev.twitter.com/docs/auth/oauth/oauth-echo -- The delegation here (using OAuth V1) is about client 1 delegating to client 2, still presumably operated by the same human user throughout. http://tools.ietf.org/html/draft-vrancken-oauth

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-18 Thread Igor Faynberg
Looks like a good description of a new use case to me! Igor On 10/17/2012 10:23 PM, zhou.suj...@zte.com.cn wrote: Hi, Thomas, Sorry for reply late. I somehow missed the emails from OAUTH list. "What may not be clear up-front from reading the UMA core spec is that there are 5 parties invol

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-17 Thread zhou . sujing
Hi, Eve Sorry for reply late. I somehow missed the emails from OAUTH list. “ (I'm not seeing Zhou's responses to you on the list, so I don't have the other proposal handy. Can Zhou or someone share the link?) ” you mean the following links? http://www.ietf.org/mail-archive/web/oauth/curr

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-17 Thread zhou . sujing
Hi, Eve Sorry for reply late. I somehow missed the emails from OAUTH list. "If the client/requesting party is literally acting on behalf of the initial RO, then it would seem to me that this is closer to the discussions of "redelegation" and Twitter Echo and such from the past. UMA's use

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-17 Thread zhou . sujing
Hi, Thomas, Sorry for reply late. I somehow missed the emails from OAUTH list. "What may not be clear up-front from reading the UMA core spec is that there are 5 parties involved (AM, Alice/RO, Host, Bob (Requesting Party) and Bob's portal/platform (Requester)). Here's a more accurate pictur

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-11 Thread Eve Maler
Behalf >> Of zhou.suj...@zte.com.cn >> Sent: Thursday, October 11, 2012 4:45 AM >> To: Eve Maler >> Cc: oauth@ietf.org WG >> Subject: Re: [OAUTH-WG] Resource owner initiated OAuth delegation >> >> >> Hi,Eve >> >> "Having an RO li

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-11 Thread Thomas Hardjono
Apologies for jumping in late. > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf > Of zhou.suj...@zte.com.cn > Sent: Thursday, October 11, 2012 4:45 AM > To: Eve Maler > Cc: oauth@ietf.org WG > Subject: Re: [OAUTH-WG] Resource owner initiated OAuth del

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-11 Thread zhou . sujing
Oct 2012, at 6:49 PM, zhou.suj...@zte.com.cn wrote: Hi,Prabath Prabath Siriwardena 2012-10-09 20:35 收件人 zhou.suj...@zte.com.cn 抄送 Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org 主题 Re: Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation On Mon, Oct 8, 2012 at 6:24

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
: > > Hi, Eve, >The requester you described corresponds to Client in OAuth, so it is still > client initiated delegation, not what Prabath wants. > > > > Eve Maler > 2012-10-11 06:54 > > 收件人 > Prabath Siriwardena > 抄送 > zhou.suj...@zte.com.cn, &q

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread zhou . sujing
收件人 zhou.suj...@zte.com.cn 抄送 Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org 主题 Re: Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation On Mon, Oct 8, 2012 at 6:24 PM, wrote: Hi, Prabath My question is since client-id is public, then it is a waste to get it by

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
l in > normal use. > > Eve > > On 9 Oct 2012, at 6:49 PM, zhou.suj...@zte.com.cn wrote: > >> >> Hi,Prabath >> >> >> Prabath Siriwardena >> 2012-10-09 20:35 >> >> 收件人 >> zhou.suj...@zte.com.cn >> 抄送 >&g

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Prabath Siriwardena
-09 20:35 > 收件人 > zhou.suj...@zte.com.cn > 抄送 > Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org > 主题 > Re: Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation > > > > > > > On Mon, Oct 8, 2012 at 6:24 PM, > <*zhou.suj...@zte.com.cn*>

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
t; Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org > 主题 > Re: Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation > > > > > > > > On Mon, Oct 8, 2012 at 6:24 PM, wrote: > > Hi, Prabath > > My question is since client-id is publ

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-09 Thread zhou . sujing
Hi,Prabath Prabath Siriwardena 2012-10-09 20:35 收件人 zhou.suj...@zte.com.cn 抄送 Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org 主题 Re: Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation On Mon, Oct 8, 2012 at 6:24 PM, wrote: Hi, Prabath My question is since

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-09 Thread Prabath Siriwardena
; regards, -Prabath > > > *Prabath Siriwardena * > > 2012-10-08 12:00 > 收件人 > zhou.suj...@zte.com.cn > 抄送 > Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org > 主题 > Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation > > > > > Hi Zhou,

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-08 Thread zhou . sujing
esource on behalf of the Resource Owner. Prabath Siriwardena 2012-10-08 12:00 收件人 zhou.suj...@zte.com.cn 抄送 Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org 主题 Re: Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation Hi Zhou, Even though client_id is public that needs to

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-08 Thread Eve Maler
(I'm not seeing Zhou's responses to you on the list, so I don't have the other proposal handy. Can Zhou or someone share the link?) Your proposal seems to require that the requester/client register with the AS (through the RS) ahead of time as well as initiating the approach to the resource at

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread Prabath Siriwardena
ent-id public?) > > > > *Prabath Siriwardena * > > 2012-10-08 09:50 > 收件人 > zhou.suj...@zte.com.cn > 抄送 > Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org > 主题 > Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation > > > > > Hi Zhou,

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread zhou . sujing
.cn 抄送 Eve Maler , oauth@ietf.org, oauth-boun...@ietf.org 主题 Re: Re: [OAUTH-WG] Resource owner initiated OAuth delegation Hi Zhou, Nice to see some common interest on this. Sure I will go through your proposal. Please find my proposal here [1]. I've added there the complete t

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread Prabath Siriwardena
Siriwardena * > 发件人: oauth-boun...@ietf.org > > 2012-10-08 08:08 > 收件人 > Eve Maler > 抄送 > oauth@ietf.org > 主题 > Re: [OAUTH-WG] Resource owner initiated OAuth delegation > > > > > Hi Eve, > > Thanks for pointers.. I've been following the work do

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread zhou . sujing
TH-WG] Resource owner initiated OAuth delegation Hi Eve, Thanks for pointers.. I've been following the work done in UMA.. Sure.. will join the webinar... BTW .. I am not quite sure UMA addresses my use case. Even in the case of UMA it's client initiated or requestor initiated... Pl

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread Prabath Siriwardena
Hi Eve, Thanks for pointers.. I've been following the work done in UMA.. Sure.. will join the webinar... BTW .. I am not quite sure UMA addresses my use case. Even in the case of UMA it's client initiated or requestor initiated... Please correct me if I am wrong... but in OAuth specification the

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread Eve Maler
Hi Prabath, As far as I know, OAuth itself generally isn't used to let one human resource owner delegate access to a different human resource owner. However, UMA (which leverages OAuth) does strive to solve exactly this use case, among other similar ones; we call this one "person-to-person shar

[OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-06 Thread Prabath Siriwardena
Hi folks, I would like to know your thoughts on the $subject.. For me it looks like a concrete use case where OAuth conceptually does address - but protocol does not well defined.. Please find [1] for further details... [1]: http://blog.facilelogin.com/2012/10/ationwhat-oauth-lacks-resource-ow