Because b64token is existing practice

-----Original Message-----
From: Julian Reschke [mailto:[email protected]] 
Sent: Wednesday, October 12, 2011 11:24 AM
To: Mike Jones
Cc: Manger, James H; [email protected]
Subject: Re: [OAUTH-WG] draft-ietf-oauth-v2-bearer-08.txt WGLC comments

On 2011-10-12 20:02, Mike Jones wrote:
> The syntax in HTTPbis is:
>      credentials = auth-scheme [ 1*SP ( b64token / #auth-param ) ]
>
> The syntax in Bearer 09 is:
>     credentials = "Bearer" 1*SP ( b64token / #auth-param )
>
> As this conforms to HTTPbis, I don't see a problem.  I think HTTPbis and 
> Bearer are both fine as-is.

The intent is that a scheme uses one of the two constructs, not both.

Bearer can't use auth-params and b64tokens in the same challenge, so it's 
unclear to me how this is supposed to work.

If you have a notation where you can express the bearer token as auth-param 
then why don't you *always* use it and get rid of the b64token construct?

Best regards, Julian

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to