Hi Dick, My interpretation from yesterday was that we were asked "Do we want to adopt this specific solution" and the answer was "no, because it's unclear if this actually solves the problem or not based on reading the draft text alone"
There's no clear definition of the problem, therefore there can't be a solution, yet. — Emelia > On 22 Sep 2026, at 17:05, Dick Hardt <[email protected]> wrote: > > Hey > > > > At the September 21 interim [1], the chairs asked if there authorization code > exfiltration is a problem to be solved. 3 said yes, 5 said no. > > > > The authorization code is a credential that we deliver in the redirect URL. > From there it can be exfiltrated through history, logs, Referer, page > JavaScript and extensions. Based on the Browser-Swapping thread [2] and the > support for Redirect Headers in December [3], I had thought there was > consensus that this is a problem. > > > > Do you think exfiltration of the authorization code is a problem this WG > should solve? > > > > /Dick > > > > [1] https://datatracker.ietf.org/meeting/interim-2026-oauth-05/session/oauth > > [2] https://mailarchive.ietf.org/arch/msg/oauth/K8Wnw08GzPstyAQAh0JmSB47pOQ/ > > [3] https://mailarchive.ietf.org/arch/msg/oauth/FFkUlOiz7I4K03pqjMfIFkxAwA8/ > > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected]
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
