Hi Emilia

The poll text was "Do people agree there is a problem to be solved"

https://datatracker.ietf.org/doc/polls-interim-2026-oauth-05-202609211300/

Slide 4 of the presentation was presented during the poll.

The poll was not adoption of the draft by the WG.

/Dick

On Tue, Sep 22, 2026 at 5:02 PM Emelia S. <[email protected]> wrote:

> Hi Dick,
>
> My interpretation from yesterday was that we were asked "Do we want to
> adopt this specific solution" and the answer was "no, because it's unclear
> if this actually solves the problem or not based on reading the draft text
> alone"
>
> There's no clear definition of the problem, therefore there can't be a
> solution, yet.
>
> — Emelia
>
> On 22 Sep 2026, at 17:05, Dick Hardt <[email protected]> wrote:
>
> Hey
>
>
> At the September 21 interim [1], the chairs asked if there authorization
> code exfiltration is a problem to be solved. 3 said yes, 5 said no.
>
>
> The authorization code is a credential that we deliver in the redirect
> URL. From there it can be exfiltrated through history, logs, Referer, page
> JavaScript and extensions. Based on the Browser-Swapping thread [2] and the
> support for Redirect Headers in December [3], I had thought there was
> consensus that this is a problem.
>
>
> Do you think exfiltration of the authorization code is a problem this WG
> should solve?
>
>
> /Dick
>
>
> [1]
> https://datatracker.ietf.org/meeting/interim-2026-oauth-05/session/oauth
>
> [2]
> https://mailarchive.ietf.org/arch/msg/oauth/K8Wnw08GzPstyAQAh0JmSB47pOQ/
>
> [3]
> https://mailarchive.ietf.org/arch/msg/oauth/FFkUlOiz7I4K03pqjMfIFkxAwA8/
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
>
>
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to