The following was submitted via the shared-copy page but does not belong with 
editorial feedback. This needs to be discussed and supported on the list before 
added the specification. I think it belongs where 'immediate' is specified.

EHL

------ Forwarded Message
From: An anonymous reader <[email protected]>
Date: Sat, 10 Jul 2010 11:01:11 -0700
To: Eran Hammer-Lahav <[email protected]>
Subject: Re: draft-ietf-oauth-v2-09 - The OAuth 2.0 Protocol


 "Colin Snover" left these comments on your copy:

draft-ietf-oauth-v2-09 - The OAuth 2.0 Protocol 
<http://r6.sharedcopy.com/6bnqq8v>


     As proposed on the ML, a new parameter to counteract the current behaviour 
of OAuth 1.0a authorization servers which is to assume that the account logged 
into the user-agent is the account that should be checked for access:

force_auth
         OPTIONAL. The parameter value must be set to "true" or "false".

         If set to "true", the authorization server MUST prompt the end-user to 
authenticate and approve access. The authorization server MUST NOT make any 
assumptions as to the identity of the entity requesting access, even if another 
automatic mechanism is available to do so (e.g. browser cookies).

         If set to "false" or not present, the authorization server MAY 
automatically grant access to the client if it is able to determine that access 
was previously granted.         link » <http://r6.sharedcopy.com/6bnqq8v#shcp21>


tools.ietf.org/html/draft-ietf-oauth-v2-09 <http://r6.sharedcopy.com/6bnqq8v>  
· Original page <http://tools.ietf.org/html/draft-ietf-oauth-v2-09>


________________________________
via sharedcopy.com <http://sharedcopy.com/?ef>

------ End of Forwarded Message
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to