Skip to content

Commit 4d4e421

Browse files
authored
Merge pull request #46 from selfissued/mbj-remove-extraneous-paragraph
Removed extraneous paragraph
2 parents 2c52151 + 78ac761 commit 4d4e421

File tree

1 file changed

+11
-9
lines changed

1 file changed

+11
-9
lines changed

Diff for: draft-ietf-oauth-resource-metadata.xml

+11-9
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@
4040
</address>
4141
</author>
4242

43-
<date day="8" month="July" year="2024" />
43+
<date day="22" month="July" year="2024" />
4444

4545
<area>Security</area>
4646
<workgroup>OAuth Working Group</workgroup>
@@ -797,14 +797,6 @@
797797
This allows the resource server to support clients that may or may not implement this specification,
798798
and allows clients to choose their preferred authentication scheme.
799799
</t>
800-
<t>
801-
A fair question is whether allowing clients to choose from among
802-
supported authentication methods represents an opportunity for a downgrade attack.
803-
Since resource servers will only enumerate authentication methods acceptable to them, by definition,
804-
any choice made by the client from among them is one that the resource server is OK with.
805-
Thus, the resource server allowing the use of different supported authentication methods
806-
does not represent an opportunity for a downgrade attack.
807-
</t>
808800
</section>
809801

810802
</section>
@@ -1563,6 +1555,16 @@
15631555
<section anchor="History" title="Document History">
15641556
<t>[[ to be removed by the RFC Editor before publication as an RFC ]]</t>
15651557

1558+
<t>
1559+
-07
1560+
<list style="symbols">
1561+
<t>
1562+
Removed extraneous paragraph about downgrade attacks discussing
1563+
an issue that's already addressed elsewhere in the specification.
1564+
</t>
1565+
</list>
1566+
</t>
1567+
15661568
<t>
15671569
-06
15681570
<list style="symbols">

0 commit comments

Comments
 (0)