CORS setup is confusing to people. I'm going to remove the web-origins
setting from the admin console. Instead there will be a on/off switch
that says "Cross-Origin Tokens (CORS)". Tokens created for those types
of clients will have the token's origins calculated by iterating over
the redirect uri list.
--
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com