Thanks for making these changes - the new spec looks really good.
In my reading, one thing stuck out - if we do immediate mode, it will need to apply to both web_server and user_agent flows. Our primary use case is for the user_agent flow (loading in an iframe on page load).
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
