It may be my misreading the spec, or making assumptions based on my cluttered mind from reading the various drafts, so apologies if I'm just confused, but...
Section 2 seems to be just sitting there. No discussion on how it fits into the spec from what I can see. It doesn't discuss how to obtain a grant, or access token, or anything. It also mentions type=web-server, which is an obsolete parameter. Section 4.1 has a grant_type=none option, which seems to cover the same scenario as Section 2 (did). I take it that section 4.1 is sort of the "2 legged OAuth" scenario. Am I correct in this? -- Andrew Arnott "I [may] not agree with what you have to say, but I'll defend to the death your right to say it." - S. G. Tallentyre
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
