62 karma · joined July 31, 2019
Regurgitating the OAuth draft don't seem that usefull imho, and why am I forced into it if I'm using http. Seems like there are plenty of usecases where un-attended thing would like to interact over http, where we usually use other things aside from OAuth.
It all probably could have been replaced by
- The Client shall implement OAuth2 - The Server may implement OAuth2
From reading your issue, I'm not holding my breath.
It all kind of seems too important to fuck up
Kind of reminds me of the browser wars during 90s where everyone tried to run the fastest an created splits in standards and browsers what we didn't really det rid of for a good 20 year or more. IE11 was around for far to long
"I’m here to (hopefully) change your mind by introducing you to a lesser-known date format called ISO 8601."
It seems so foreign to me, and most people i know, to use anything but ISO8601 or RFC3339. Might be, as with most things, that we here up in the Nordics simply are used to it.