Hi all, 

revision of draft-lodderstedt-oauth-par (Pushed Authorization Requests) was 
just published. 

Here is the list of changes:
List client_id as one of the basic parameters
Explicitly forbid request_uri in the processing rules
Clarification regarding client authentication and that public clients are 
allowed
Added option to let clients register per-authorization request redirect URIs
General clean up and wording improvements
I will present this draft in Singapore and would be happy if the working group 
would consider adoption of this joint work (Co-authors: David Tonge, Nat 
Sakimura, Brian Campbell, Filip Skokan) as WG draft.

best regards,
Torsten. 

> Begin forwarded message:
> 
> From: [email protected]
> Subject: New Version Notification for draft-lodderstedt-oauth-par-01.txt
> Date: 3. November 2019 at 17:04:23 CET
> To: "Nat Sakimura" <[email protected]>, "Brian Campbell" 
> <[email protected]>, "Torsten Lodderstedt" 
> <[email protected]>, "Dave Tonge" <[email protected]>, "Filip Skokan" 
> <[email protected]>
> 
> 
> A new version of I-D, draft-lodderstedt-oauth-par-01.txt
> has been successfully submitted by Torsten Lodderstedt and posted to the
> IETF repository.
> 
> Name:         draft-lodderstedt-oauth-par
> Revision:     01
> Title:                OAuth 2.0 Pushed Authorization Requests
> Document date:        2019-11-02
> Group:                Individual Submission
> Pages:                14
> URL:            
> https://www.ietf.org/internet-drafts/draft-lodderstedt-oauth-par-01.txt
> Status:         https://datatracker.ietf.org/doc/draft-lodderstedt-oauth-par/
> Htmlized:       https://tools.ietf.org/html/draft-lodderstedt-oauth-par-01
> Htmlized:       
> https://datatracker.ietf.org/doc/html/draft-lodderstedt-oauth-par
> Diff:           
> https://www.ietf.org/rfcdiff?url2=draft-lodderstedt-oauth-par-01
> 
> Abstract:
>   This document defines the pushed authorization request endpoint,
>   which allows clients to push the payload of an OAuth 2.0
>   authorization request to the authorization server via a direct
>   request and provides them with a request URI that is used as
>   reference to the data in a subsequent authorization request.
> 
> 
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> The IETF Secretariat
> 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to