I don't know if he was holding things back. I believe he wanted OAuth 2.0 to be as simple as possible, which wouldn't make the spec very flexible, but it would be easy to implement correctly.
I believe the committee had a lot of different ideas about how certain problems should be approached and instead of choosing 1 solution they either decided to keep some things open for the implementer or allowed several solutions to a problem as part of the spec.
Comments
I don't know if he was holding things back. I believe he wanted OAuth 2.0 to be as simple as possible, which wouldn't make the spec very flexible, but it would be easy to implement correctly.
I believe the committee had a lot of different ideas about how certain problems should be approached and instead of choosing 1 solution they either decided to keep some things open for the implementer or allowed several solutions to a problem as part of the spec.