RE: [xacml] Using XACML Policies to Express Scope in OAuth
I think you are making the OAuth model very complex here by trying to add in XACML, there are size restrictions for the implicit flows that would prohibit XACML type policies, there are size restriction on refresh tokens (that would contain the original asked for scope), etc.