[Openid-specs-ab] [Bitbucket] Issue #873: session 4.1. Can we use opbs with http (not httponly) (openid/connect)

Mike Jones Michael.Jones at microsoft.com
Tue Oct 15 22:33:31 UTC 2013

(Adding Phuong Le to the To: line, in case he isn’t subscribed to openid-specs-ab.)

Can one of you propose text?  I tried to work on this last night when preparing the release candidates, and couldn’t figure out exactly what is wanted/needed.  It would be good to get this updated by the time we publish final specifications for Core, etc.

                                                            -- Mike

From: Mike Jones
Sent: Monday, October 14, 2013 11:45 PM
To: openid-specs-ab at lists.openid.net
Cc: George Fletcher
Subject: RE: [Bitbucket] Issue #873: session 4.1. Can we use opbs with http (not httponly) (openid/connect)

George or Phuong, could one of you please provide specific proposed text changes for this issue?

                                                            -- Mike

From: Phuong Le [mailto:issues-reply at bitbucket.org]
Sent: Thursday, September 19, 2013 10:05 PM
To: Mike Jones
Subject: Re: [Bitbucket] Issue #873: session 4.1. Can we use opbs with http (not httponly) (openid/connect)


Phuong Le commented on issue #873:

session 4.1. Can we use opbs with http (not httponly)<https://bitbucket.org/openid/connect/issue/873/session-41-can-we-use-opbs-with-http-not>

Yes, that's reason I would confirm whether if it is possible to store the opbs on browser and what the opbs' value should be to avoid the security issue.

View this issue<https://bitbucket.org/openid/connect/issue/873/session-41-can-we-use-opbs-with-http-not> or add a comment by replying to this email.

Unwatch this issue<https://bitbucket.org/openid/connect/issue/873/unwatch/mbj/a8746e6417c83baf247203db3c7943b0d9a03b87/> to stop receiving email updates.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20131015/045908d8/attachment.html>

More information about the Openid-specs-ab mailing list