The following was submitted via the shared-copy page but does not belong with editorial feedback. This needs to be discussed and supported on the list before added the specification. I think it belongs where 'immediate' is specified.
EHL ------ Forwarded Message From: An anonymous reader <[email protected]> Date: Sat, 10 Jul 2010 11:01:11 -0700 To: Eran Hammer-Lahav <[email protected]> Subject: Re: draft-ietf-oauth-v2-09 - The OAuth 2.0 Protocol "Colin Snover" left these comments on your copy: draft-ietf-oauth-v2-09 - The OAuth 2.0 Protocol <http://r6.sharedcopy.com/6bnqq8v> As proposed on the ML, a new parameter to counteract the current behaviour of OAuth 1.0a authorization servers which is to assume that the account logged into the user-agent is the account that should be checked for access: force_auth OPTIONAL. The parameter value must be set to "true" or "false". If set to "true", the authorization server MUST prompt the end-user to authenticate and approve access. The authorization server MUST NOT make any assumptions as to the identity of the entity requesting access, even if another automatic mechanism is available to do so (e.g. browser cookies). If set to "false" or not present, the authorization server MAY automatically grant access to the client if it is able to determine that access was previously granted. link » <http://r6.sharedcopy.com/6bnqq8v#shcp21> tools.ietf.org/html/draft-ietf-oauth-v2-09 <http://r6.sharedcopy.com/6bnqq8v> · Original page <http://tools.ietf.org/html/draft-ietf-oauth-v2-09> ________________________________ via sharedcopy.com <http://sharedcopy.com/?ef> ------ End of Forwarded Message
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
