One reason is that you may want to exchange tokens in a batch, whereas you 
typically can only sign requests individually.

On Jun 29, 2010, at 6:12 PM, Marius Scurtescu wrote:

> On Tue, Jun 29, 2010 at 8:22 AM, Eran Hammer-Lahav <[email protected]> 
> wrote:
>> 
>> The assertion grant type is really the grant type extension point. Libraries 
>> should treat it as a way to support custom grant types. One of the things I 
>> would like to see someone draft is how to use OAuth 1.0 tokens to obtain 
>> OAuth 2.0 tokens using the assertion type. For example, the assertion type 
>> can be "http://oauth.net/1.0/token"; , and the assertion itself is some form 
>> of the token and signature (or secrets) concatenated into a string (this 
>> will maintain the 1.0 security while transitioning to 2.0). This is just a 
>> straw man.
>> 
>> It is important that libraries support this extensibility with some form of 
>> a hook or handler so that clients can make requests using assertions from 
>> outside the library.
> 
> An OAuth 1 token assertion as described above would achieve the same
> thing as the suggested bridge endpoint. Do you see any advantages on
> using an assertion as opposed to a standard OAuth 1 signed request?
> 
> Marius
> _______________________________________________
> OAuth mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to