I noticed (don't ask how) two tiny little things in the POST body in
the example in section 4.1.3.  Currently it has:

     grant_type=assertion&client_id=s6BhdRkqt3&client_secret=diejdsks&

     assertion_type=urn%3Aoasis%3Anames%sAtc%3ASAML%3A2.0%3Aassertion&
     assertion=PHNhbWxwOl...[ommited for brevity]...ZT4%3D

Omitted has a typo/misspelling and "sA" isn't a valid hex number.  I"d
suggest the following as an alternative:

     grant_type=assertion&client_id=s6BhdRkqt3&client_secret=diejdsks&
     assertion_type=urn%3Aoasis%3Anames%3Atc%3ASAML%3A2.0%3Aassertion&
     assertion=PHNhbWxwOl...[omitted for brevity]...ZT4%3D

Thanks,
Brian
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to