Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-03-07 Thread Eran Hammer
-lucent.com To: oauth@ietf.orgmailto:oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response for response_type=unknown Could there be a potential security hole in providing an error response? (Not that I see it, but many problems in the past

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread matake@gmail
, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response for response_type=unknown Could there be a potential security hole in providing an error response? (Not that I see it, but many problems in the past had been caused by helpful responese.) Igor On 2/20/2012 11

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread matake@gmail
is usually echoing back the user data, or allowing user enumeration for example. Care is required, but you don't have a ton of options here. From: Igor Faynberg igor.faynb...@alcatel-lucent.com To: oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread John Bradley
enumeration for example. Care is required, but you don't have a ton of options here. From: Igor Faynberg igor.faynb...@alcatel-lucent.com To: oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response for response_type=unknown

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread matake@gmail
, or allowing user enumeration for example. Care is required, but you don't have a ton of options here. From: Igor Faynberg igor.faynb...@alcatel-lucent.com To: oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread Buhake Sindi
enumeration for example. Care is required, but you don't have a ton of options here. -- *From:* Igor Faynberg igor.faynb...@alcatel-lucent.com *To:* oauth@ietf.org *Sent:* Monday, February 20, 2012 9:37 AM *Subject:* Re: [OAUTH-WG] Quick question about error

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread Buhake Sindi
of options here. -- *From:* Igor Faynberg igor.faynb...@alcatel-lucent.com *To:* oauth@ietf.org *Sent:* Monday, February 20, 2012 9:37 AM *Subject:* Re: [OAUTH-WG] Quick question about error response for response_type=unknown Could there be a potential

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-21 Thread John Bradley
here. From: Igor Faynberg igor.faynb...@alcatel-lucent.com To: oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response for response_type=unknown Could there be a potential security hole in providing an error response

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-20 Thread William Mills
Respond with an error in protocol.  Thta won't include a redirect, and the client has to know what to do. From: nov matake n...@matake.jp To: oauth WG oauth@ietf.org Sent: Monday, February 20, 2012 6:11 AM Subject: [OAUTH-WG] Quick question about error

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-20 Thread Igor Faynberg
Could there be a potential security hole in providing an error response? (Not that I see it, but many problems in the past had been caused by helpful responese.) Igor On 2/20/2012 11:57 AM, William Mills wrote: Respond with an error in protocol. Thta won't include a redirect, and the

Re: [OAUTH-WG] Quick question about error response for response_type=unknown

2012-02-20 Thread William Mills
Faynberg igor.faynb...@alcatel-lucent.com To: oauth@ietf.org Sent: Monday, February 20, 2012 9:37 AM Subject: Re: [OAUTH-WG] Quick question about error response for response_type=unknown Could there be a potential security hole in providing an error response?  (Not that I see it, but many