Skip to content

Commit 859ba6b

Browse files
committed
update changelog
1 parent 8a38f38 commit 859ba6b

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

draft-ietf-oauth-browser-based-apps.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1340,13 +1340,11 @@ Document History
13401340

13411341
-23
13421342

1343-
* Addressed feedback from Gen-ART review
1344-
* Addressed feedback from opsdir review
1343+
* Ensure acronyms and other specifications are defined and referenced on first use, and added to terminology
1344+
* Clarified mailicious JavaScript is the basis of the threat analysis earlier in the document
13451345
* Clarified why filesystem storage of private key is a concern
13461346
* Clarified JS runtimes in intro
13471347
* Addressed feedback from secdir review
1348-
* Clarified mailicious JavaScript is the basis of the threat analysis earlier in the document
1349-
* Ensure acronyms and other specifications are defined and referenced on first use, and added to terminology
13501348
* Clarified that the specific attacks described are the relevant ones for this document because they are OAuth-specific
13511349
* Described the relationship to session fixation attacks
13521350
* Clarified that section 8 is talking about OAuth tokens specifically
@@ -1356,6 +1354,9 @@ Document History
13561354
* Clarified the intent of storing the refresh token in a web worker
13571355
* Mention explicitly access token and refresh token instead of "set of tokens" on first use per section
13581356
* Slightly rephrased Web Worker section to not sound like a recommendation
1357+
* Editorial edits to remove the phrase "perfect storage mechanism"
1358+
* Fixed references
1359+
* Addressed all feedback from the genart, opsdir, artart, secdir, and httpdir reviews
13591360

13601361
-22
13611362

0 commit comments

Comments
 (0)