aaronpk / oauth-first-party-apps

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-first-party-apps
Other
10 stars 8 forks source link

Should we allow 3rd party apps as long as the only challenge method is passkey? #9

Closed gffletch closed 1 year ago

gffletch commented 1 year ago

The current draft lists the requirements as "MUST NOT" allow 3rd party clients to use this specification. Do we want to be that strong? Or leave it as is for now and change it later when there is more data and maybe implementation experience?

aaronpk commented 1 year ago

Pieter and I discussed this today, we are leaning towards sticking with the current limitation of 1st party apps, since mentioning 3rd party apps opens up a lot more items that would need to be solved in this context. If someone did want to create an extension to solve the 3rd party use cases that would be best done as a different draft.