aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
9 stars 7 forks source link

Interaction with "native SSO" #64

Closed yaronf closed 2 weeks ago

yaronf commented 3 months ago

Sec. 1.1: the paragraph that talks about Native SSO is about what you shouldn't do. It would be nice to also say what you can do, i.e. whether there's some possible integration between the two approaches.

Related to that, the text about multiple applications and an SDK does not directly contradict Sec. 9.7.3 but the two could be improved, e.g. by clarifying the cases when Native SSO is not applicable.

aaronpk commented 2 weeks ago

I'm not sure I understand the problem. The point of section 1.1 is to describe when not to use this spec. It then also says Native SSO might be a better solution. Do you have any suggestions for how to make this clearer?

yaronf commented 2 weeks ago

I re-read the two sections and I think they're fine. Closing.