On Sun, Nov 24, 2019 at 8:18 PM Ryan Kelly <[email protected]> wrote:

>
> > The "matches as prefix of one of the URLs" part of Paragraph 3 seems a
>> bit unclear as well, given that there is no requirement that the
>> "locations" elements be well-formed URLs. Is this is simple string prefix
>> match, or some sort of path matching based on the components of the URL?
>>
>> simple string match
>>
>
> Does the AS need to take any particular care about resource names that
> might accidentally be prefixes of each other, such as "
> https://example.com/payments"; and "https://example.com/payme";?  That
> seems really contrived, but perhaps I'm just not creative enough to think
> of a more realistic example.
>


That particular example is maybe somewhat contrived but that kind of thing
will undoubtedly occur at some point. I do think that some sort of path
matching would be more appropriate for this.

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to