No benefit. This would just be the "2.0 way" of doing it.

EHL

> -----Original Message-----
> From: Marius Scurtescu [mailto:[email protected]]
> Sent: Tuesday, June 29, 2010 6:13 PM
> To: Eran Hammer-Lahav
> Cc: OAuth WG ([email protected])
> Subject: OAuth 1.0 token assertion to OAuth 2.0 token (was: Draft -09)
> 
> On Tue, Jun 29, 2010 at 8:22 AM, Eran Hammer-Lahav
> <[email protected]> wrote:
> >
> > The assertion grant type is really the grant type extension point. Libraries
> should treat it as a way to support custom grant types. One of the things I
> would like to see someone draft is how to use OAuth 1.0 tokens to obtain
> OAuth 2.0 tokens using the assertion type. For example, the assertion type
> can be "http://oauth.net/1.0/token"; , and the assertion itself is some form
> of the token and signature (or secrets) concatenated into a string (this will
> maintain the 1.0 security while transitioning to 2.0). This is just a straw 
> man.
> >
> > It is important that libraries support this extensibility with some form of 
> > a
> hook or handler so that clients can make requests using assertions from
> outside the library.
> 
> An OAuth 1 token assertion as described above would achieve the same
> thing as the suggested bridge endpoint. Do you see any advantages on using
> an assertion as opposed to a standard OAuth 1 signed request?
> 
> Marius
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to