New version available! "The OAuth 2.1 Authorization Framework" ietf.org/archive/id/draft-ieโ€ฆ by @DickHardt @aaronpk @tlodderstedt #oauth #oauth2 #ietf
2
11
22
Noticed that the resource owner password and implicit grants are removed from the 2.1 (For obvious reasons :)) But doesn't that make the OAuth 2.1 framework backward incompatible with OAuth 2.0? OAuth 2.1 kind of gives the feeling its a slight(minor) change from OAuth 2.0
2
1
Password and Implicit are already not part of OAuth 2.0 as described by the Security Best Current Practice. The 2.1 update is leaving them out so that you don't have to first learn about them and then read another doc telling you not to use them.
1
3
Thanks @aaronpk for the clarification ๐Ÿ‘ So OAuth 2.1 is essentially OAuth 2.0 without the naughty bits :)
2
2
That's one way to say it ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

Oct 6, 2021 ยท 3:21 PM UTC

2