Musings on Digital Identity

Category: OAuth

OAuth 2.0 Bearer Token Specification draft -02

OAuth logoI’ve published draft 02 of the bearer token specification. This incorporates consensus feedback received to date. It contains no normative changes relative to draft 01. Your feedback is solicited. Specific changes were:

  • Changed terminology from “token reuse” to “token capture and replay”.
  • Removed sentence “Encrypting the token contents is another alternative” from the security considerations since it was redundant and potentially confusing.
  • Corrected some references to “resource server” to be “authorization server” in the security considerations.
  • Generalized security considerations language about obtaining consent of the resource owner.
  • Broadened scope of security considerations description for recommendation “Don’t pass bearer tokens in page URLs”.
  • Removed unused reference to OAuth 1.0.
  • Updated reference to framework specification and updated David Recordon’s e-mail address.
  • Removed security considerations text on authenticating clients.
  • Registered the “OAuth2” OAuth access token type and “oauth_token” parameter.

The draft is available at these locations:

This version is explicitly not ready for working group last call, as changes may need to be made due to the open issues in the framework spec about the removal of the Client Assertion Credentials and OAuth2 HTTP Authentication Scheme.

OAuth 2.0 Bearer Token Specification Draft -01

OAuth logoDraft -01 of the OAuth 2.0 Bearer Token specification is now available. This version is intended to accompany OAuth 2.0 draft -11. This draft is based upon the September 3rd preliminary OAuth 2.0 draft -11 by Eran Hammer-Lahav, with input from David Recordon and several others. It includes an extensive Security Considerations section, for which Hannes Tschofenig gets significant credit.

The draft is available at these locations:

If any of you believe that you should be added to the Acknowledgments in Appendix A, please drop me a note and I’ll be glad to add you.

Page 12 of 12

Powered by WordPress & Theme by Anders Norén