Section 10 of the OAuth spec says it applies only to requests for
Request Tokens and Access Tokens, not access requests. But I think we
need to add some error flows to XEP-0235. What are the appropriate error
conditions when rejecting an access request?
/psa
smime.p7s
Description: S/MIME Cryptographic Signature