We've talked about issuing different client secrets for use with different flows. We haven't actually implemented it yet and prefer using something like TPM on devices which support it. A different secret is at least better than nothing for apps which can't reliably keep secrets and don't have something like a TPM.
--David On Thu, Jun 10, 2010 at 12:42 PM, Eran Hammer-Lahav <[email protected]> wrote: > Some of the flows require/allow a client secret while others disallow it > (when the client has no secure means to keep it secret). My question is, do > you plan to issue different credentials for different flows (with or without > secret) or allow the same set to be used, sometimes with and sometimes > without a secret based on the flow? > > EHL > _______________________________________________ > OAuth mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/oauth > _______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
