Hi All,

Here's my question:
http://stackoverflow.com/questions/2377541/why-must-we-change-temporary-credentials-for-token-credentials-in-oauth


"Can't the server just "upgrade" the temporary credentials to token
credentials and retain the same key and secret?

The client can then start doing authenticated calls right away after
the recieving the callback from the server stating that the temporary
credentials has been "upgraded".

Of cause if the temporary credentials have not be upgrade (i.e. client
doesn't wait for callback) the authenticated call fails.

So the question is why make an extra call to the server after the
callback to "exchange" temporary credentials for token credentials?"

-- 
You received this message because you are subscribed to the Google Groups 
"OAuth" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/oauth?hl=en.

Reply via email to