On Tue, Jun 29, 2010 at 6:30 PM, Luke Shepard <[email protected]> wrote: > One reason is that you may want to exchange tokens in a batch, whereas you > typically can only sign requests individually.
How does the assertion grant type help in this case? As far as I can tell this also allows you to exchange only one token. Marius > > On Jun 29, 2010, at 6:12 PM, Marius Scurtescu wrote: > >> On Tue, Jun 29, 2010 at 8:22 AM, Eran Hammer-Lahav <[email protected]> >> wrote: >>> >>> The assertion grant type is really the grant type extension point. >>> Libraries should treat it as a way to support custom grant types. One of >>> the things I would like to see someone draft is how to use OAuth 1.0 tokens >>> to obtain OAuth 2.0 tokens using the assertion type. For example, the >>> assertion type can be "http://oauth.net/1.0/token" , and the assertion >>> itself is some form of the token and signature (or secrets) concatenated >>> into a string (this will maintain the 1.0 security while transitioning to >>> 2.0). This is just a straw man. >>> >>> It is important that libraries support this extensibility with some form of >>> a hook or handler so that clients can make requests using assertions from >>> outside the library. >> >> An OAuth 1 token assertion as described above would achieve the same >> thing as the suggested bridge endpoint. Do you see any advantages on >> using an assertion as opposed to a standard OAuth 1 signed request? >> >> Marius >> _______________________________________________ >> OAuth mailing list >> [email protected] >> https://www.ietf.org/mailman/listinfo/oauth > > _______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
