Section 4.1.1, which deals with requesting an access token using an authorization code, doesn't list the client_id and client_secret parameters at all, yet mentions verifying them in paragraph form, and they are included in the example.
-- Andrew Arnott "I [may] not agree with what you have to say, but I'll defend to the death your right to say it." - S. G. Tallentyre
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
