- 
                Notifications
    
You must be signed in to change notification settings  - Fork 16
 
Closed
Description
Summarized action items based on review:
https://mailarchive.ietf.org/arch/msg/oauth/_vsDr-xTHDR9xL-HyUlQ-rkK4o8/
- clarify why filesystem storage of private key is a concern. (Question about whether there is another secure storage mechanism or remote server as a private storage mechanism)
 - add PKCE to terminology section
 - clarify that "JavaScript applications" and "malicious JavaScript" is talking about JS vs non-JS browser runtimes
 - add reference to section 5.1 in "when discussing attack patterns"
 - add CORS and CSP to terminology
 
Metadata
Metadata
Assignees
Labels
No labels