You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Mar 20, 2019. It is now read-only.
The client identifier is encoded using the "application/x-www-form-urlencoded" encoding algorithm per Appendix B, and the encoded value is used as the username; the client password is encoded using the same algorithm and used as the password.
Is this done in DotNetOpenAuth? If I read the specification correctly, that means a client ID such as my::client::id would be encoded to my%3A%3Aclient%3A%3Aid and a client secret such as my::client::secret would be encoded to my%3A%3Aclient%3A%3Asecret. This would then form the username:password pair for use in HTTP Basic Authentication, i.e. my%3A%3Aclient%3A%3Aid:my%3A%3Aclient%3A%3Asecret would be base64 encoded and put in the Authorization header.
A username containing colon does not seem to work with DotNetOpenAuth. Have I misunderstood something?
Take a look at this section in the OAuth 2.0 RFC: http://tools.ietf.org/html/rfc6749#section-2.3.1, specifically:
Is this done in DotNetOpenAuth? If I read the specification correctly, that means a client ID such as
my::client::idwould be encoded tomy%3A%3Aclient%3A%3Aidand a client secret such asmy::client::secretwould be encoded tomy%3A%3Aclient%3A%3Asecret. This would then form the username:password pair for use in HTTP Basic Authentication, i.e.my%3A%3Aclient%3A%3Aid:my%3A%3Aclient%3A%3Asecretwould be base64 encoded and put in theAuthorizationheader.A username containing colon does not seem to work with DotNetOpenAuth. Have I misunderstood something?