Standard: 5.1. UserInfo Request : Reference section number to Messages must be wrong.

Issue #511 resolved
hideki nara created an issue

In [[http://openid.bitbucket.org/openid-connect-standard-1_0.html#anchor19 | December 22, 2011 version of Standard Draft 07]]

" ...

Client SHOULD send the UserInfo Request defined in section 3.3 of the OpenID Connect Messages 1.0 [OpenID.Messages] either in HTTP GET or POST request.

... " * Maybe [[http://openid.bitbucket.org/openid-connect-messages-1_0.html#userinfo_ep | 2.4 of Messages]] * There isn't any particular description about HTTP method in the Messages.

Comments (7)

  1. John Bradley

    It should be Sec 2.4.1 of Messages.

    Messages is binding independent, so should not have anything about the HTTP method.

    Are you saying the binding description in standard sec 5.1 is unclear?

  2. hideki nara reporter

    Thanks

    • 2.4.1 is fine.
    • It might be my English comprehension matter, but Standard 5.1 mentions about HTTP method while Messages doesn't. So it's more natural for me we don't mention HTTP method in Standard.
  3. John Bradley

    Standard is where the HTTP binding is specified. So it is saying GET or POST can be used to send the message defined in messages 2.4.1.

    It is trying to say this is a OAuth bearer profile resource, use that to access the endpoint. The API parameters are defined in Messages 2.4.1.

  4. Log in to comment