Re: [OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Todd W Lainhart
operation and its protections. Todd Lainhart Rational software IBM Corporation 550 King Street, Littleton, MA 01460-1250 1-978-899-4705 2-276-4705 (T/L) lainh...@us.ibm.com From: Martin Ždila To: oauth@ietf.org, Date: 08/30/2013 03:42 AM Subject:[OAUTH-WG] Unclear parts in

Re: [OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Dick Hardt
On Fri, Aug 30, 2013 at 3:41 PM, Martin Ždila wrote: > Hello > > There are some unclear parts in OAuth 2.0 specification. > > *1.* In 4.3. (B) there is following statement: > >When making the request, the client >authenticates with the authorization server. > > > In 4.3.2 there is followin

[OAUTH-WG] Unclear parts in OAuth 2.0 specification

2013-08-30 Thread Martin Ždila
Hello There are some unclear parts in OAuth 2.0 specification. *1.* In 4.3. (B) there is following statement: When making the request, the client authenticates with the authorization server. In 4.3.2 there is following statement: If the client type is confidential or the client was i