wrap_callback matching

2 views
Skip to first unread message

Marius Scurtescu

unread,
Jan 8, 2010, 4:29:46 PM1/8/10
to oauth-...@googlegroups.com
It is not clear from the spec how exactly the callback URL is matched
against the registered one.

My understanding is that the matching rules are Authorization Server
specific, and clients using a specific server must play by those
rules. If that's the case, maybe the spec should make it explicit.

As a side question, why not require strict equality when matching,
clients can always use wrap_client_state?

Marius

Reply all
Reply to author
Forward
0 new messages