…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol. Applications MAY use the [ IndieAuth ] extension which supports endpoint discovery from a URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discovery Micropub defin…
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol. Applications MAY use the [ IndieAuth ] extension which supports endpoint discovery from a URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discovery Micropub defin…
…ntent-type application/x-www-form-urlencoded , as described in section 4.1.3 of RFC6749 For public apps , authentication is not possible (and thus not required), since a client with no secret cannot prove its identity when it issues a call. (The end-to-end system can still be sec…
… Response If the authorization server grants this request (see Section 5.1 in [ RFC6749 ] for the detailed description), it returns HTTP 200 OK status code with content type "application/json" consisting of a JSON object containing the access token and its expiry lifetime (1EdTec…
…cord provider services are secured using OAuth 2.0 Bearer Token authorization [ RFC6749 ], and conformant Comprehensive Learner Record consumers must also support bearer token authorization. Additionally, some providers and consumers may support additional authorization mechanism…
… Response If the authorization server grants this request (see Section 5.1 in [ RFC6749 ] for the detailed description), it returns HTTP 200 OK status code with content type "application/json" consisting of a JSON object containing the access token and its expiry lifetime (1EdTec…
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol, including the [ IndieAuth ] extension which supports endpoint discovery from a URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discovery A Micropub client SHOULD …
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol, including the [ IndieAuth ] extension which supports endpoint discovery from a URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discovery Micropub defines a link r…
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol. Applications MAY use the [ IndieAuth ] extension which supports OAuth 2.0 endpoint discovery from a profile URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discov…
…plicit Grant type, with PoP (Proof-of-Possession) Token type, as described in [ RFC6749 ] and [ OAUTH-POP-KEY-DISTRIBUTION ]. The OAuth Client and the Auhorization Server roles are defined in [ RFC6749 ] Section 1.1. If [ RFC7635 ] is used in the WebRTC context then the OAuth Cli…
…erver", "access token", and "protected resource" are inherited from OAuth 2.0 [ RFC6749 ]. We use the term 'sign' (or 'signature') to denote both a keyed message digest and a digital signature operation. . Generating a JSON Object from an HTTP Request This specification uses JSON…
…ActivityStreams 对象的 id oauthAuthorizationEndpoint 客户端到服务端交互 使用 OAuth 2.0 不记名令牌[ RFC6749 ] [ RFC6750 ] 进行身份验证, 此端点指定一个 URI,通过浏览器完成认证的用户可在该 URI 上获取新的授权许可。 oauthTokenEndpoint 客户端到服务端交互 使用 OAuth 2.0 不记名令牌 [ RFC6749 RFC6750 进行身份验证, 此端点指定一个 URI,客户端可以在该 URI 获取访问令牌。 provideClientKey 若身份验…
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol, including the [ IndieAuth ] extension which supports endpoint discovery. See Obtaining an Access Token for more details. Micropub requests are authenticated by including a Bearer T…
…der to get an access token. Authorization SHOULD be handled via the OAuth 2.0 [ RFC6749 ] protocol, including the [ IndieAuth ] extension which supports endpoint discovery from a URL. See Obtaining an Access Token for more details. 5.3 Endpoint Discovery A Micropub client SHOULD …
…nation headers MUST be supported They MAY support Token Refresh as defined in [ RFC6749 ]. If so, a call to refresh token MUST return a new access token. They MAY support Token Revocation as defined in [ RFC7709 ]. If so, a revocation MUST cause all of subsequent calls to return …