oauth-wg / oauth-v2-1

OAuth 2.1 is a consolidation of the core OAuth 2.0 specs
https://oauth.net/2.1/
Other
53 stars 27 forks source link

Move normative text from security considerations inline in the doc #64

Open aaronpk opened 3 years ago

aaronpk commented 3 years ago

Security considerations should be reserved for implementation details

ioggstream commented 3 years ago

Moreover, the Summary of recommendations should not duplicate mandatory text. I'd replace it with a table referencing the actual spec sections.