Skip to content

Remove obsolete / insecure OAuth2 flows from this spec #27

Description

@GeorgDangl

Here, we're listing two flows: https://github.com/buildingSMART/foundation-API#221-obtaining-authentication-information

  • implicit_grant, which has been effectively deprecated, or at least it's usage is heavily discouraged
  • resource_owner_password_credentials_grant, which never really was considered secure in scenarios where you did not control all services involved

This was brought up in the meeting today, and we should just remove it from the spec completely.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions