Skip to content

Releases: oauth-wg/oauth-browser-based-apps

Draft 22: Addressing AD review

17 Jan 22:55
Compare
Choose a tag to compare
  • Addressed AD review (#64)
  • Moved RFC6819 reference to informal
  • Added missing references from prose
  • Replaced references to living standards with references to snapshots

Updated references

23 Dec 14:56
Compare
Choose a tag to compare
draft-ietf-oauth-browser-based-apps-21

fixed references from shepherd writeup review

Draft 19

20 Oct 21:03
Compare
Choose a tag to compare
  • Updated references

Draft 18

01 May 17:38
Compare
Choose a tag to compare
  • Addressed last call comments from Justin Richer and Andy Barlow
  • Updated description of the benfits of Token-Mediating Backend pattern
  • Added SVG diagrams in HTML version
  • Added privacy considerations for BFF pattern
  • Consistent use of "grant type", "grant" and "flow"

Draft 17

28 Feb 23:17
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: draft-ietf-oauth-browser-based-apps-16...draft-ietf-oauth-browser-based-apps-17

Draft 16

17 Feb 00:23
Compare
Choose a tag to compare
  • Applied editorial changes from Filip Skokan and Louis Jannett
  • Clarified when cookie encryption applies
  • Added a section with security considerations on the use of postMessage

Draft 15

23 Oct 15:19
Compare
Choose a tag to compare

Huge thanks to @philippederyck for the massive amount of work that went into this update!

  • Restructured document to have top-level recommended and discouraged architecture patterns
  • Consolidated guidelines for public JS clients in a single section
  • Added more focus on best practices at the start of the document
  • Added Philippe De Ryck as an author

Draft 13

13 Mar 19:00
Compare
Choose a tag to compare
  • Corrected some uses of "DOM"
  • Consolidated CSRF recommendations into normative part of the document
  • Added links from the summary into the later sections
  • Described limitations of Service Worker storage
  • Minor editorial improvements

Draft 12

07 Dec 21:34
Compare
Choose a tag to compare
draft-ietf-oauth-browser-based-apps-12

update changelog

Draft 11

13 Sep 17:37
Compare
Choose a tag to compare
  • Added a new architecture pattern: Token Mediating Backend
  • Revised and added clarifications for the Service Worker pattern
  • Editorial improvements in descriptions of the different architectures
  • Rephrased headers and rearranged some sections