<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Verdana;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
tt
{mso-style-priority:99;
font-family:"Courier New";
color:#003366;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">While working on the spelling and grammar check, I noticed the following in redirect_uri definitions. While I hate to bring this up while we’re trying to finish the Implementer’s Drafts, this is potentially a recall-class issue, so I wanted
to raise it now, rather than have it come up later.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Messages, Basic, and Implicit say:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">redirect_uri<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">REQUIRED. Redirection URI to which the response will be sent. This MUST be pre-registered with the OpenID Provider.
<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Standard says:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">redirect_uri<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">REQUIRED. Redirection URI to which the response will be sent. The Scheme, Host, Path, and Query Parameter segments of this URI MUST match one
of the </span><tt><span lang="EN" style="font-size:12.0pt">redirect_uris</span></tt><span lang="EN" style="font-family:"Verdana","sans-serif";color:black"> registered for the
</span><tt><span lang="EN" style="font-size:12.0pt">client_id</span></tt><span lang="EN" style="font-family:"Verdana","sans-serif";color:black"> in the
<a href="file:///C:\mbj\DSG\OpenID\openid-connect-standard-1_0.html#OpenID.Registration">
<span style="text-decoration:none">OpenID Connect Dynamic Client Registration 1.0</span></a> [OpenID.Registration] specification.
<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Dynamic Registration says:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">redirect_uris<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span lang="EN" style="font-family:"Verdana","sans-serif";color:black">REQUIRED. Array of redirection URIs values used in the Authorization Code and Implicit grant types. One of these registered redirection URI
values MUST match the Scheme, Host, and Path segments of the </span><span lang="EN" style="font-family:"Courier New";color:#003366">redirect_uri</span><span lang="EN" style="font-family:"Verdana","sans-serif";color:black"> parameter value used in each Authorization
Request. <o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Should Messages, Basic, and Implicit be changed to match Standard? That’s my sense of the situation, but wanted to get others’ input before doing so.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> Thanks,<o:p></o:p></p>
<p class="MsoNormal"> -- Mike<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>