Skip to content

FAPI_Meeting_Notes_2019 03 27_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes (2019-03-27)

Date & Time: 2019-03-27 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/321819862

The meeting was called to order at 14:05 UTC.

  • Attending: * Bjorn, Dave, Joseph, Torsten
  • Guests:
  • Regrets:
  • Agenda was agreed
  • Discussion around external organisations
  • Daniel, John and Torsten writing a draft for sender-constraining in a token bound like way but without token binding.
  • Using application level signatures
  • New header that carries a JWT that contains the target url, the method,
  • Dave explained about the schema and the history from durable data API
  • Not looked at JARM yet
  • Joseph asked about implementation - (Connect2Id & OpenID Provider)
  • Action to raise ticket about whether JARM is well integrated with part 2
  • Launch on 1st April for FAPI testing
  • Torsten to update draft with this other approach
  • Change name to rich authorisation data

https://github.com/openid/fapi/issues/163 Security BCP assumes passive attackers, whereas FAPI assumes otherwise.

  • Pacific call next week. Atlantic call in 2 weeks time.

Clone this wiki locally