oauth-wg / oauth-browser-based-apps

Best practices for OAuth in Browser-Based Apps
https://datatracker.ietf.org/doc/html/draft-ietf-oauth-browser-based-apps
Other
22 stars 12 forks source link

Feedback #46

Closed 0xandybarlow closed 2 months ago

0xandybarlow commented 3 months ago

Overall the spec reads very well, I didn't have trouble following.

I did spot a missing word perhaps? And also I was curious if there was a better way to describe the intent behind "Authenticated Encryption with Authenticated Data" statements - cipher? suite? algorithm? I couldn't decide on a better way - feel free to reject!

Great work!

philippederyck commented 3 months ago

Thank you for your feedback @0xandybarlow. I have incorporated the missing word in PR #45, which is pending anyway. The text about AEAD encryption does need to be improved, but this is already pending in issue #44.

@aaronpk This PR can be closed, since both items are addressed/being tracked in an issue.