w3c / wot-security

a repo exclusively for security to better manage issues and security considerations for WoT
https://w3c.github.io/wot-security/
18 stars 22 forks source link

Consider OAuth2 "device" flow #173

Closed mmccool closed 3 years ago

mmccool commented 4 years ago

There is a new OAuth2 flow for devices that we may want to consider supporting, the "device" flow. Review and make a decision.

zolkis commented 4 years ago

Then update on https://github.com/w3c/wot-scripting-api/issues/214

mmccool commented 4 years ago

There is a PR for this now that we plan to merge this week: https://github.com/w3c/wot-thing-description/pull/927

mmccool commented 3 years ago

Device flow has been added, and has been merged into TD spec 1.1 draft. Note: we do need two implementations however before it can make it into REC.