Skip to content

Conversation

@jogu
Copy link
Contributor

@jogu jogu commented Aug 13, 2025

Clarify that authorization code flow section now that we have a non-frontchannel method (IAE) to obtain authorization_code.

Clarify that the recommendation to use PAR means PAR or IAE.

closes #613

@jogu jogu added this to the Final 1.0 milestone Aug 13, 2025
@jogu jogu force-pushed the pkce-etc-clarifications branch from 706c6e2 to efba25c Compare August 13, 2025 11:36
# Token Endpoint {#token-endpoint}

The Token Endpoint issues an Access Token and, optionally, a Refresh Token in exchange for the Authorization Code that Client obtained in a successful Authorization Response. It is used in the same manner as defined in [@!RFC6749]. Implementers SHOULD follow the best current practices for OAuth 2.0 Security given in [@!BCP240].
The Token Endpoint issues an Access Token and, optionally, a Refresh Token in exchange for the Authorization Code that Client obtained in a successful Authorization Response. It is used in the same manner as defined in [@!RFC6749]. Implementers SHOULD follow the best current practices for OAuth 2.0 Security given in [@!BCP240], see (#securitybcp).
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed on today's WG call; consensus around merging this sentence and the 710 sentence.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually the sentence on line 710 is specific to IAE so that's not needed. Don't think it's worth raising a separate PR just to add a link to the securitybcp section here. We can just bundle this all in with the IAE changes.

@jogu jogu added the iae Items related to Interactive Authorization Endpoint label Aug 14, 2025
@Sakurann Sakurann modified the milestones: Final 1.0, 1.1 Aug 21, 2025
jogu added a commit that referenced this pull request Sep 22, 2025
@jogu jogu mentioned this pull request Sep 22, 2025
Clarify that authorization code flow section now that we have a
non-frontchannel method (IAE) to obtain authorization_code.

Clarify that the recommendation to use PAR means PAR or IAE.
@jogu jogu force-pushed the pkce-etc-clarifications branch from efba25c to 05e5455 Compare October 20, 2025 17:22
@jogu
Copy link
Contributor Author

jogu commented Oct 20, 2025

I've updated this PR to apply the changes to the 1.1 spec file.

@jogu jogu merged commit e35469d into main Oct 23, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

iae Items related to Interactive Authorization Endpoint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Improvements to clauses about PKCE

6 participants