[Owncloud] WebDAV with OAuth 2.0 support

fkooman at tuxed.net fkooman at tuxed.net
Sun Oct 28 14:17:07 UTC 2012


On Sun, Oct 28, 2012 at 3:11 PM, Michael Gapczynski <mtgap at owncloud.com> wrote:
> We had earlier decided that we needed to implement OAuth 1.0a for the API
> instead of OAuth 2.0. This is because of the fact that the security in OAuth
> 2.0 is only done by TLS and we shouldn't force this requirement on users.

Oh I though we decided that using OAuth 2.0 without TLS is not less
secure than using Basic Authentication without TLS... Actually using
OAuth 2.0 without TLS is a little more secure than using Basic Auth.

Regards,
François



More information about the Owncloud mailing list