Hi Emilia The poll text was "Do people agree there is a problem to be solved"
https://datatracker.ietf.org/doc/polls-interim-2026-oauth-05-202609211300/ Slide 4 of the presentation was presented during the poll. The poll was not adoption of the draft by the WG. /Dick On Tue, Sep 22, 2026 at 5:02 PM Emelia S. <[email protected]> wrote: > Hi Dick, > > My interpretation from yesterday was that we were asked "Do we want to > adopt this specific solution" and the answer was "no, because it's unclear > if this actually solves the problem or not based on reading the draft text > alone" > > There's no clear definition of the problem, therefore there can't be a > solution, yet. > > — Emelia > > On 22 Sep 2026, at 17:05, Dick Hardt <[email protected]> wrote: > > Hey > > > At the September 21 interim [1], the chairs asked if there authorization > code exfiltration is a problem to be solved. 3 said yes, 5 said no. > > > The authorization code is a credential that we deliver in the redirect > URL. From there it can be exfiltrated through history, logs, Referer, page > JavaScript and extensions. Based on the Browser-Swapping thread [2] and the > support for Redirect Headers in December [3], I had thought there was > consensus that this is a problem. > > > Do you think exfiltration of the authorization code is a problem this WG > should solve? > > > /Dick > > > [1] > https://datatracker.ietf.org/meeting/interim-2026-oauth-05/session/oauth > > [2] > https://mailarchive.ietf.org/arch/msg/oauth/K8Wnw08GzPstyAQAh0JmSB47pOQ/ > > [3] > https://mailarchive.ietf.org/arch/msg/oauth/FFkUlOiz7I4K03pqjMfIFkxAwA8/ > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > >
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
