On Mon, Jun 28, 2010 at 9:37 PM, Manger, James H <[email protected]> wrote: > > For instance, why not define a SAML HTTP authentication mechanism: > > Authorization: SAML a=<base64url-encoded SAML assertion>
This came up in another thread, but SAML assertions could be too large to be passed through an HTTP header. Other than that, your suggestion really simplifies things. Marius _______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
