[OAUTH-WG] draft-ietf-oauth-security-topics: Migration strategies for deprecated password grant

2019-11-28 Thread Jorge Bernal
Hi all, We are currently discussing[1] an implementation of oAuth for WordPress and what this would mean for our mobile apps[2]. It was noted that the new recommendation will completely discourage the use of the password grant. While I agree in principle that this is a good thing overall, we will

Re: [OAUTH-WG] draft-ietf-oauth-security-topics

2018-06-10 Thread Torsten Lodderstedt
Hi Doug, Am 22.05.18 um 07:48 schrieb McDorman, Doug: I attached 2 diffs which should help highlight the changes. thanks, that helped a lot! To summarize: Added 1.1. Notational Conventions Section 3.1.1. Attacks on Authorization Code Grant FROM control, say "https://www.evil.com";. TO co