4 ms·
Funnily enough, I actually suggested we adopt something like GREASE for OAuth parameters: https://mailarchive.ietf.org/arch/msg/oauth/Rqxs-QDqqdQkt36SO915gJJU0d
by nmadden 6y ago
Funnily enough, I actually suggested we adopt something like GREASE for OAuth parameters: https://mailarchive.ietf.org/arch/msg/oauth/Rqxs-QDqqdQkt36SO915gJJU0dI/ https://mailarchive.ietf.org/arch/msg/oauth/Rqxs-QDqqdQkt36S...
There wasn’t a lot of support.
- tialaramex 6y agoThat list archive suggests that although there wasn't a clamour of applause for the idea at least some people were receptive. However it also suggests that there were plenty of more subtle incompatibilities which GREASing just this one place wouldn't solve. It also seems like you admit that in other places ForgeRock is also doing something that's unsound: > (Basically there are quite a few clients that use JSON mapping tools with enum types - List<JWSAlgorithm>. I know there are parts of our own codebase where we do this too).
- nmadden 6y agoWell like any large codebase there will be things that need improving. The handful of places where we have similar issues are relatively unlikely to cause a real problem in the near future.