Authorization header for client credentials?

10 views
Skip to first unread message

Markus Sabadello

unread,
Oct 2, 2010, 7:48:11 AM10/2/10
to oauth-le...@googlegroups.com
Hi there!

At our PDS Project, we're currently looking into using Leeloo for building an OAuth 2.0 endpoint on top of our Personal Data Store.

Looking great so far, just one quick question:
Does the library support reading client credentials from an HTTP Authorization: header, as described in section 2.1 of http://tools.ietf.org/html/draft-ietf-oauth-v2-10 ?

Looking at OAuthRequest.java, I suspect that it only supports reading the client_id and client_secret parameters from the HTTP body, but I may be wrong..

best,
Markus
--
blog: http://danubechannel.com
phone: +43 664 3154848

Maciej Machulak

unread,
Oct 2, 2010, 9:40:40 AM10/2/10
to oauth-le...@googlegroups.com
Hi Markus,

It's great to see the leeloo will be used in your project!

We don't support reading client credentials from the Authorization
header. We'll add that shortly.

Cheers,
Maciej

--
Maciej Machulak
email: maciej....@gmail.com
tel: +48 602 45 31 44
tel: +44 7999 606 767

Markus Sabadello

unread,
Oct 2, 2010, 9:58:11 AM10/2/10
to oauth-le...@googlegroups.com
Okay no problem, we don't need that.. Was just wondering if I read the code correctly.

thanks
Markus
Reply all
Reply to author
Forward
0 new messages