Scope needs clarification

Issue #562 resolved
Nat Sakimura created an issue

Current text

This document specifies the requirements for confidential Clients to securely obtain OAuth tokens from Authorization Servers and securely use those tokens to access REST APIs at Resource Servers.

This is kind of OK, but it also appears as if this document just specifies the requirements for clients, which is not the case. A large part of the document specifies the requirements for servers.

This is a non-normative editorial change but still desirable to be implemented.

Comments (5)

  1. Log in to comment