On Sat, Jul 10, 2010 at 11:55 PM, Brian Eaton <[email protected]> wrote: > > Let's use a format like this: > > WWW-Authenticate: OAuth2 base64(<json>) > > Or even just: > > WWW-Authenticate: OAuth2 > > Seriously.
Looks good. Doesn't matter which the WG picks. > 1) dropping the name="value" syntax won't break the internet, because > widely deployed schemes have already done it. Fully agree. > 2) "realm" is not necessary in order to have a successful > authentication protocol. Indeed. So far, it looks like "realm" is necessary to have an unsuccessful authentication protocol. > > As far as I can tell, there is no good reason for RFC 2617 to specify > the syntax it does. RFC 2617 adopts constraints that predate widespread Unicode adoption. > It's convenient for digest auth, and kind of a > pain everywhere else. > It's not convenient for Digest, and Digest doesn't work anyway. -- Robert Sayre "I would have written a shorter letter, but I did not have the time." _______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
