+1 for a defined extension mechanism

maybe I didn't understand but I would have thought the "pape:error" would be...

"pape:error"="Invalid max_auth_age format."

does the message itself need to be namespaced?

Thanks,
George

On 6/8/10 12:45 AM, Nat Sakimura wrote:
Defining an Extension Mechanism for both request and response would generally be useful.

Some basic design principles:

- no name space through type URI: fixed registered string for extensions.
e.g., for Open Graph, perhaps use og:variable_names OR og_variable names where either "og:" or "og_" is the type prefix. (I kind of prefer ":" over "_" as a separator since in CGI "-" and "_" will be identical, and in PHP GPC parameters "." and "_" are identical. Also, we are using "_" in the variable names already. )
- no cross interactions with other extensions

I think it should be added as Chapter 7 or so, which means Security Considerations will be chapter 8.

Following is the straw-man.

7. Extension Mechanism

Additional parameters MAY be defined for any request and response.
The parameter names MUST start with a parameter prefix separated by a colon ":".

For example:

pape:max_auth_age

Each extension MUST define its own error messages and MUST return them through
the prefixed "error" parameter.

For example:

"pape:error":"Invalid max_auth_age format."


cheers,

Nat






--
Nat Sakimura (=nat)
http://www.sakimura.org/en/
http://twitter.com/_nat_en


_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to