10. 参考文献 (References)
本节列出本文档引用的规范性和信息性参考文献. 为保持引用可核验性, 文献条目的作者姓名, 英文题名, 出版物名称, RFC 编号, DOI, URL 和日期等元数据按原文保留. 中文说明用于标明这些条目是协议规范, 标准文档, 实现资料或背景资料, 读者可据此追溯原始来源.
规范性参考文献覆盖 OAuth 2.0 原生应用配置依赖的核心规则: URI 语法、OAuth 2.0 授权框架、HTTP/1.1 消息语法、URI scheme 注册流程、PKCE 以及 RFC 2119/8174 关键词. 这些文献决定重定向 URI、授权请求、授权码交换和公共客户端防护机制应如何实现.
资料性参考文献提供安全背景和平台实现经验, 包括 OAuth 2.0 威胁模型、动态客户端注册、AppAuth 库以及不同操作系统上的示例应用. 对原生应用开发者来说, 这些文献有助于理解为什么推荐外部用户代理、为什么需要 PKCE, 以及如何避免嵌入式 WebView 或自定义 URI scheme 带来的风险.
10.1. 规范性参考文献 (Normative References)
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, \https://www.rfc-editor.org/info/rfc2119\``.
[RFC3986] Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, DOI 10.17487/RFC3986, January 2005, \https://www.rfc-editor.org/info/rfc3986\``.
[RFC6749] Hardt, D., Ed., "The OAuth 2.0 Authorization Framework", RFC 6749, DOI 10.17487/RFC6749, October 2012, \https://www.rfc-editor.org/info/rfc6749\``.
[RFC7230] Fielding, R., Ed. and J. Reschke, Ed., "Hypertext Transfer Protocol (HTTP/1.1): Message Syntax and Routing", RFC 7230, DOI 10.17487/RFC7230, June 2014, \https://www.rfc-editor.org/info/rfc7230\``.
[RFC7595] Thaler, D., Ed., Hansen, T., and T. Hardie, "Guidelines and Registration Procedures for URI Schemes", BCP 35, RFC 7595, DOI 10.17487/RFC7595, June 2015, \https://www.rfc-editor.org/info/rfc7595\``.
[RFC7636] Sakimura, N., Ed., Bradley, J., and N. Agarwal, "Proof Key for Code Exchange by OAuth Public Clients", RFC 7636, DOI 10.17487/RFC7636, September 2015, \https://www.rfc-editor.org/info/rfc7636\``.
[RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, \https://www.rfc-editor.org/info/rfc8174\``.
10.2. 资料性参考文献 (Informative References)
[RFC6819] Lodderstedt, T., Ed., McGloin, M., and P. Hunt, "OAuth 2.0 Threat Model and Security Considerations", RFC 6819, DOI 10.17487/RFC6819, January 2013, \https://www.rfc-editor.org/info/rfc6819\``.
[RFC7591] Richer, J., Ed., Jones, M., Bradley, J., Machulak, M., and P. Hunt, "OAuth 2.0 Dynamic Client Registration Protocol", RFC 7591, DOI 10.17487/RFC7591, July 2015, \https://www.rfc-editor.org/info/rfc7591\``.
[AppAuth] OpenID Connect Working Group, "AppAuth", September 2017, \https://openid.net/code/AppAuth\``.
[AppAuth.iOSmacOS] Wright, S., Denniss, W., et al., "AppAuth for iOS and macOS", February 2016, \https://openid.net/code/AppAuth-iOS\``.
[AppAuth.Android] McGinniss, I., Denniss, W., et al., "AppAuth for Android", February 2016, \https://openid.net/code/AppAuth-Android\``.
[SamplesForWindows] Denniss, W., "OAuth for Apps: Samples for Windows", July 2016, \https://openid.net/code/sample-oauth-apps-for-windows\``.