On Sat, Jul 10, 2010 at 11:55 PM, Brian Eaton <[email protected]> wrote:
>
> Let's use a format like this:
>
> WWW-Authenticate: OAuth2 base64(<json>)
>
> Or even just:
>
> WWW-Authenticate: OAuth2
>
> Seriously.

Looks good. Doesn't matter which the WG picks.

> 1) dropping the name="value" syntax won't break the internet, because
> widely deployed schemes have already done it.

Fully agree.

> 2) "realm" is not necessary in order to have a successful
> authentication protocol.

Indeed. So far, it looks like "realm" is necessary to have an
unsuccessful authentication protocol.

>
> As far as I can tell, there is no good reason for RFC 2617 to specify
> the syntax it does.

RFC 2617 adopts constraints that predate widespread Unicode adoption.

> It's convenient for digest auth, and kind of a
> pain everywhere else.
>

It's not convenient for Digest, and Digest doesn't work anyway.

-- 

Robert Sayre

"I would have written a shorter letter, but I did not have the time."
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to