Skip to content

Releases: oauth-wg/draft-ietf-oauth-resource-metadata

draft-ietf-oauth-resource-metadata-05

03 May 23:35
171139e
Compare
Choose a tag to compare

draft-ietf-oauth-resource-metadata-04

26 Apr 16:20
Compare
Choose a tag to compare

Address WGLC comments.

draft-ietf-oauth-resource-metadata-03

01 Feb 12:40
Compare
Choose a tag to compare

draft-ietf-oauth-resource-metadata-02

25 Jan 03:05
Compare
Choose a tag to compare
  • Switched from concatenating .well-known to the end of the resource identifier to inserting it between the host and path components of it.
  • Have WWW-Authenticate return resource_metadata rather than resource.

draft-ietf-oauth-resource-metadata-01

21 Oct 02:29
Compare
Choose a tag to compare
  • Renamed scopes_provided to scopes_supported
  • Added security consideration for scopes_supported
  • Use BCP 195 for TLS recommendations
  • Clarified that resource metadata can be used by clients and authorization servers
  • Updated references
  • Added security consideration recommending audience-restricted access tokens
  • Mention FAPI Message Signing as a use case for publishing signing keys

draft-ietf-oauth-resource-metadata-00

06 Sep 23:36
Compare
Choose a tag to compare

draft-ietf-oauth-resource-metadata-00

draft-jones-oauth-resource-metadata-04

07 Jul 23:36
4da5fe9
Compare
Choose a tag to compare
Merge pull request #1 from selfissued/mbj-www-authenticate

Added WWW-Authenticate functionality from draft-parecki-oauth-authorization-server-discovery-00

draft-jones-oauth-resource-metadata-03

Aaron Parecki added Security Considerations on Server-Side Request Forgery (SSRF) and Phishing.
Added Aaron Parecki as an author.