Skip to content

Commit 74a7462

Browse files
author
Justin Richer
committedNov 3, 2012
added client type information to security discussion
1 parent dc687ce commit 74a7462

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed
 

‎draft-richer-oauth-instance.xml

+3-3
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
<?rfc inline="yes"?>
1111
<?rfc compact="yes"?>
1212
<?rfc subcompact="no"?>
13-
<rfc category="exp" docName="draft-richer-oauth-instance-00" ipr="trust200902">
13+
<rfc category="exp" docName="draft-richer-oauth-instance-01" ipr="trust200902">
1414
<front>
1515
<title abbrev="oauth-instance">OAuth Client Instance Extension</title>
1616

@@ -115,10 +115,10 @@
115115
<section anchor="Security" title="Security Considerations">
116116
<t>The instance_name and instance_description parameters MUST be treated
117117
as self-asserted information from the client and MUST NOT be treated as
118-
a replacement for a client credential as defined in <xref
118+
a replacement for a client credential or client_id as defined in <xref
119119
target="I-D.ietf-oauth-v2">OAuth 2</xref>. Instead, the instance
120120
parameters MUST be treated with a level of trust appropriate to the end
121-
client.</t>
121+
client, whether public or private.</t>
122122

123123
<t>When this information is displayed to the user, the authorization
124124
server MUST present it in such a way as to make clear to the end user

0 commit comments

Comments
 (0)
Please sign in to comment.