There are a couple of cases where you could have a much simpler API than HTTP,
implicit is one of those. All in all though it's easier to leave everything
under the same rules, instead of having to define a new protocol for thing like
implicit.
I think that answers your question?
-bill
________________________________
From: Security Developer <[email protected]>
To: [email protected]
Sent: Sunday, January 29, 2012 3:25 AM
Subject: [OAUTH-WG] Question related Implicit Grant Type
Hi,
My question is, why web hosted resource is needed to extract the access token?
Thanks for your time.
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth