-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2017 03 15
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date & Time: 2017-03-15 14:00 UTC
Location: GoToMeeting https://global.gotomeeting.com/join/321819862
Agenda
- 1. Roll Call
- 2. Adoption of the Agenda (Dave)
- 3. Drafts
- 4. External Orgs
- 5. AOB
The meeting was called to order at 14:05 UTC.
- Present: Nat, John, Tom, Bjorn, Joseph, Dave.
- Regrets: Henrik
- Guest:
- Adopted as is
- Sacha has opened a pull request
- Consensus to change "can" to "may"
- WG discussed new draft for JWT Pop Token Usage <https://tools.ietf.org/html/draft-sakimura-oauth-jpop-01>
- Discussion around the use of "Common Name" rather than "Distinguished Name"
- Dave to circulate with UK Open Banking for feedback
- WG discussed whether there should be "mandatory to implement" sections of the spec
- WG decided that it was important that the client only need to support a small number of PoP methods - even if AS supported many
- WG discussed how access tokens would be presented - Bearer vs Jpop. Draft to be reviewed to ensure this is clear. Feedback requested on feasibility of support within time constraints.
- WG discussed Issue #72
- WG agreed that where possible the implementation must support token binding and if not supported must require hybrid flow
- Draft to be adjusted
- N/A
- N/A
- N/A
- FAPI Spec is in strong consideration
- Need to work closely to ensure that the spec balances security requirements and real world implementation issues
Followings were not discussed.
- No other external orgs were discussed
- Next call is Pacific shift and is in next week.
The meeting adjourned at 15:01 UTC.