4 ms·
This is sounding like a repeat of the ambiguity from the other OAuth specs, leading to bugs, non-interoperability, and security problems. Would you please send
by part1of2 6y ago
This is sounding like a repeat of the ambiguity from the other OAuth specs, leading to bugs, non-interoperability, and security problems.
Would you please send your comments to the working group?
- brazzledazzle 6y agoMaybe the assumption is that a complimentary standards like OIDC are necessary and expected?
- btilly 6y agoYou say it like that ambiguity is a bad thing. I came to understand OAuth2 much better when I realized that it exists to make the lives of big companies easier, and to make the lives of small developers possible. If BigCo only offers an OAuth2 API, then developers will figure it out because they have no choice. And from the point of view of big companies, what matters is that they implement something that meets their needs, which they can pretend is a standard. Ambiguities give big companies the freedom to do the different things that they want to do while everyone claims, "We're following the standard!"
- Serow225 6y agoding ding ding
- chairmanwow1 6y agoOAuth 2 implementations are bizarrely different and frequently custom. Absolute nightmare to figure out the subtle differences based on who you are talking to
- bostik 6y agoThank you, good point. I did.