Skip to main content

Last Call Review of draft-ietf-oauth-browser-based-apps-22
review-ietf-oauth-browser-based-apps-22-genart-lc-fossati-2025-01-26-00

Request Review of draft-ietf-oauth-browser-based-apps
Requested revision No specific revision (document currently at 27)
Type IETF Last Call Review
Team General Area Review Team (Gen-ART) (genart)
Deadline 2025-02-04
Requested 2025-01-21
Requested by Deb Cooley
Authors Aaron Parecki , Philippe De Ryck , David Waite
I-D last updated 2026-07-09 (Latest revision 2026-07-06)
Completed reviews Secdir IETF Last Call review of -14 by Watson Ladd (diff)
Genart IETF Last Call review of -22 by Thomas Fossati (diff)
Artart IETF Last Call review of -22 by Marc Blanchet (diff)
Opsdir IETF Last Call review of -22 by Qin Wu (diff)
Secdir IETF Last Call review of -22 by Watson Ladd (diff)
Httpdir IETF Last Call review of -22 by Martin Thomson (diff)
Rtgdir IETF Last Call review of -22 by Matthew Bocci (diff)
Assignment Reviewer Thomas Fossati
State Completed
Request IETF Last Call review on draft-ietf-oauth-browser-based-apps by General Area Review Team (Gen-ART) Assigned
Posted at https://mailarchive.ietf.org/arch/msg/gen-art/sSHZs4W5y6Fhyp8OxFNlaDlEevI
Reviewed revision 22 (document currently at 27)
Result Ready w/nits
Completed 2025-01-26
review-ietf-oauth-browser-based-apps-22-genart-lc-fossati-2025-01-26-00
I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://wiki.ietf.org/en/group/gen/GenArtFAQ>.

Document: draft-ietf-oauth-browser-based-apps-22
Reviewer: Thomas Fossati
Review Date: 2025-01-26
IETF LC End Date: 2025-02-04
IESG Telechat date: Not scheduled for a telechat

Summary:

This is a BCP for browser-based apps that use OAuth 2.0.
It's a companion to BCP212, which contains similar recommendations for
OAuth 2.0 native apps.

This document is very clearly written, exhaustive, and well-organised.
From a Gen-ART perspective, it's ready to ship.
Many thanks to the editors and the oauth WG.

One question for the editors and WG regarding the BCP status: is
this doc going into BCP212 or does it get its own BCP number?

Major issues: none

Minor issues: none

Nits/editorial comments:

One editorial nit regarding the use of the term "scenario" in sentences
like:

    "scenarios that attackers can use"
    "[...] scenarios that an attacker can execute"

To my (non-native) ears, to "use/execute a scenario" sounds a bit
weird :-) Maybe "attack _strategies_ that an attacker can _exploit_"?

Apart from that, I have packed a bunch of small fixes into a PR [1].

[1] https://github.com/oauth-wg/oauth-browser-based-apps/pull/65