According to this logic, everyone should be called a credential - access token, 
refresh token, authorization code, etc. 

Having too many similar terms is confusing and a mistake I refuse to repeat. 

As for the so called bugs, so far most of your feedback is non-normative or has 
little implementation impact.

I'll incorporate whatever I can and the rest will have to get consensus and 
wait a month. 

EHL



On Jul 11, 2010, at 2:59, Brian Eaton <[email protected]> wrote:

> On Sat, Jul 10, 2010 at 8:03 PM, Eran Hammer-Lahav <[email protected]> 
> wrote:
>> I think authorization credential is going to confuse most readers. The spec
>> refers to credentials almost exclusively when dealing with identifier and
>> password (client, end-user), or as a general term for client authentication.
>> Authorization is specific to the end-user authorization endpoint and will be
>> confusing when used with assertions and other grant types.
> 
> This doesn't hold water.  "authorization credential" is consistent
> with existing practice and definition:
> 
> http://www.ietf.org/rfc/rfc2828.txt
> 
>   $ credential(s)
>      (I) Data that is transferred or presented to establish either a
>      claimed identity or the authorizations of a system entity. (See:
>      authentication information, capability, ticket.)
> 
>> Note that since this term impacts the name of the current 'grant_type'
>> parameter, changing it means code changes.
> 
> Given the number of bugs in the -09 spec, I don't think this matters.
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to