Re: Fwd: Protocol Action: 'Token Binding over HTTP' to Proposed Standard (draft-ietf-tokbind-https-18.txt)

On 15/07/18 04:28, Mark Nottingham wrote:
> FYI. Has anyone reviewed this from an HTTP perspective?
> 

I have done some irregular reviews vis-a-vis the RFC 723x and 7541
requirements, and loosely following the Unbearable WG discussions.

There are some necessary ambiguities since HTTP has a number of
use-cases which are incompatible with bound tokens. But overall
implementations compliant with HTTP should handle messages containing
bound tokens safely, and binding implementations compliant with that
document should be sane HTTP participants.

AYJ

Received on Sunday, 15 July 2018 06:22:29 UTC