4 ms·
As posted by someone downthread [1], there's an ongoing effort to update the OAuth 2.0 spec with changes since, lessons learned, and best practices [2], in what
by niftich 6y ago
As posted by someone downthread [1], there's an ongoing effort to update the OAuth 2.0 spec with changes since, lessons learned, and best practices [2], in what's currently being called OAuth 2.1. Some more rationale and resources on oauth.net [3].
[1] https://news.ycombinator.com/item?id=23083245 https://news.ycombinator.com/item?id=23083245 [2] https://tools.ietf.org/html/draft-parecki-oauth-v2-1-02 https://tools.ietf.org/html/draft-parecki-oauth-v2-1-02 [3] https://oauth.net/2.1/ https://oauth.net/2.1/
- abhishektwr 6y agoThanks for the pointer. I am not sure if OAuth 2.1 is part of working group yet. Nonetheless, a good consolidated read compared to reading 20 different RFC specs.