Standard - client type is confidential (Editorial)

Issue #244 resolved
Casper Biering created an issue

Are there any need for an undefined "client type" and "confidential", since we already have "was issued client credentials (or assigned other authentication requirements)".

Comments (4)

  1. Casper Biering reporter

    In the standard spec you have e.g. the following sentence:

    "If the client type is confidential or was issued client credentials (or assigned other authentication requirements), the client MUST authenticate with the Authorization Server as described in Section 3.2.1 of OAuth 2.0 [OAuth.2.0]."

    I suggest replacing it with:

    "If the client was issued credentials (or assigned other authentication requirements), the client MUST authenticate with the Authorization Server as described in Section 3.2.1 of OAuth 2.0 [OAuth.2.0]."

    Otherwise some kind of explanation of what a client type is and what makes it confidential would be needed.

  2. Log in to comment