Hi Torsten, yes the use case in question is payment-based as well.

Your suggestion for the client to infer one-time usage from a missing expires_in contradicts the general consensus of this thread does it not?

paul

On 1/17/12 11:38 AM, [email protected] wrote:
Hi,

isn't one-time semantics typically associated with certain requests on certain 
resources/resource types. I therefore would assume the client to know which 
tokens to use one-time only. The authz server should not return an expires_in 
paramter. We for example use one time access tokens for payment transactions.

What would such an extension specify?

regards,
Torsten.
Gesendet mit BlackBerry® Webmail von Telekom Deutschland

-----Original Message-----
From: Paul Madsen<[email protected]>
Sender: [email protected]
Date: Tue, 17 Jan 2012 08:23:37
To: Richer, Justin P.<[email protected]>
Cc: OAuth WG<[email protected]>
Subject: Re: [OAUTH-WG] Access Token Response without expires_in

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to