Skip to content

Commit

Permalink
Merge pull request #46 from selfissued/mbj-remove-extraneous-paragraph
Browse files Browse the repository at this point in the history
Removed extraneous paragraph
  • Loading branch information
selfissued authored Jul 23, 2024
2 parents 2c52151 + 78ac761 commit 4d4e421
Showing 1 changed file with 11 additions and 9 deletions.
20 changes: 11 additions & 9 deletions draft-ietf-oauth-resource-metadata.xml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@
</address>
</author>

<date day="8" month="July" year="2024" />
<date day="22" month="July" year="2024" />

<area>Security</area>
<workgroup>OAuth Working Group</workgroup>
Expand Down Expand Up @@ -797,14 +797,6 @@
This allows the resource server to support clients that may or may not implement this specification,
and allows clients to choose their preferred authentication scheme.
</t>
<t>
A fair question is whether allowing clients to choose from among
supported authentication methods represents an opportunity for a downgrade attack.
Since resource servers will only enumerate authentication methods acceptable to them, by definition,
any choice made by the client from among them is one that the resource server is OK with.
Thus, the resource server allowing the use of different supported authentication methods
does not represent an opportunity for a downgrade attack.
</t>
</section>

</section>
Expand Down Expand Up @@ -1563,6 +1555,16 @@
<section anchor="History" title="Document History">
<t>[[ to be removed by the RFC Editor before publication as an RFC ]]</t>

<t>
-07
<list style="symbols">
<t>
Removed extraneous paragraph about downgrade attacks discussing
an issue that's already addressed elsewhere in the specification.
</t>
</list>
</t>

<t>
-06
<list style="symbols">
Expand Down

0 comments on commit 4d4e421

Please sign in to comment.