Re: [Imap-protocol] OAUTH and IMAP

"David Harris" <[email protected]>
Newsgroups gmane.mail.imap.general
Organization Pegasus Mail, Dunedin NZ
Message-ID <[email protected]>
Tyro alert! Sorry to be thick here - I'll try to keep it brief.

On 30 Apr 2014 at 10:40, Joshua Cranmer wrote:

> My suggestion, which I think got misunderstood, was that instead of
> relying on a pre-registration mechanism for the client ID, IMAP clients
> should be able to construct a client ID somehow from the IMAP ID that
> they send out. I didn't intend to imply that the client ID should be
> extracted by the server from observing an IMAP ID on the transaction. 

Could you explain what "IMAP ID" you're talking about here? Is this 
something specific to the OAUTH2 specification, or has some kind of ID 
been added to post-RFC3501 IMAP while I was asleep?

Secondly, could someone send me a link showing the intended use of 
OAUTH in an IMAP implementation? Am I correct in assuming that you are 
intended to submit a user's GMail short-term token to login to GMail instead 
of using a username/password or other SASL mechanism?

Finally, could someone comment on how real any of this is? The Wikipedia 
article on OAUTH (I know, I know - Wikipedia is Wikipedia, but it's useful 
despite all its shortcomings) paints a picture of a vague, fractured, 
poorly-designed mechanism being torn apart by internal bickering and 
infighting.

   http://en.wikipedia.org/wiki/OAuth

Links to overview sources that could help bring me up to speed on the broad 
issues would be gratefully received.

Cheers!

-- David --

------------------ David Harris -+- Pegasus Mail ----------------------
Box 5451, Dunedin, New Zealand | e-mail: [email protected]
           Phone: +64 3 453-6880 | Fax: +64 3 453-6612

Thought for the day:
    A penny saved is ridiculous.



_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.