This repository was archived by the owner on Oct 18, 2025. It is now read-only.
File tree Expand file tree Collapse file tree 1 file changed +11
-9
lines changed Expand file tree Collapse file tree 1 file changed +11
-9
lines changed Original file line number Diff line number Diff line change 4040 </address >
4141 </author >
4242
43- <date day =" 8 " month =" July" year =" 2024" />
43+ <date day =" 22 " month =" July" year =" 2024" />
4444
4545 <area >Security</area >
4646 <workgroup >OAuth Working Group</workgroup >
797797 This allows the resource server to support clients that may or may not implement this specification,
798798 and allows clients to choose their preferred authentication scheme.
799799 </t >
800- <t >
801- A fair question is whether allowing clients to choose from among
802- supported authentication methods represents an opportunity for a downgrade attack.
803- Since resource servers will only enumerate authentication methods acceptable to them, by definition,
804- any choice made by the client from among them is one that the resource server is OK with.
805- Thus, the resource server allowing the use of different supported authentication methods
806- does not represent an opportunity for a downgrade attack.
807- </t >
808800 </section >
809801
810802 </section >
15631555 <section anchor =" History" title =" Document History" >
15641556 <t >[[ to be removed by the RFC Editor before publication as an RFC ]]</t >
15651557
1558+ <t >
1559+ -07
1560+ <list style =" symbols" >
1561+ <t >
1562+ Removed extraneous paragraph about downgrade attacks discussing
1563+ an issue that's already addressed elsewhere in the specification.
1564+ </t >
1565+ </list >
1566+ </t >
1567+
15661568 <t >
15671569 -06
15681570 <list style =" symbols" >
You can’t perform that action at this time.
0 commit comments