According to this logic, everyone should be called a credential - access token, refresh token, authorization code, etc.
Having too many similar terms is confusing and a mistake I refuse to repeat. As for the so called bugs, so far most of your feedback is non-normative or has little implementation impact. I'll incorporate whatever I can and the rest will have to get consensus and wait a month. EHL On Jul 11, 2010, at 2:59, Brian Eaton <[email protected]> wrote: > On Sat, Jul 10, 2010 at 8:03 PM, Eran Hammer-Lahav <[email protected]> > wrote: >> I think authorization credential is going to confuse most readers. The spec >> refers to credentials almost exclusively when dealing with identifier and >> password (client, end-user), or as a general term for client authentication. >> Authorization is specific to the end-user authorization endpoint and will be >> confusing when used with assertions and other grant types. > > This doesn't hold water. "authorization credential" is consistent > with existing practice and definition: > > http://www.ietf.org/rfc/rfc2828.txt > > $ credential(s) > (I) Data that is transferred or presented to establish either a > claimed identity or the authorizations of a system entity. (See: > authentication information, capability, ticket.) > >> Note that since this term impacts the name of the current 'grant_type' >> parameter, changing it means code changes. > > Given the number of bugs in the -09 spec, I don't think this matters. _______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
