-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2021 05 12_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date & Time: 2020-05-12 14:00 UTC
- Location: GoToMeeting https://global.gotomeeting.com/join/321819862
- Note URI: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2021-04-07_Atlantic
Agenda
The meeting was called to order at 14:05 UTC.
- Attending: Bjorn, Dave, Nat, Ali, Brian, Daniel, Dima, Filip, Francis, Joseph, Kosuke, Lukasz, Ralph, Stuart, Takahiko, Torsten
- Regrets: Vinod Anandan (self)
- Guest:
- Adopted as is.
- Not open invite. Need to drop email to Joseph to get an invite.
- A few presentations on FAPI.
May 11 - 13. Dave Tonge spoke.
Sizable directed funding for certification test. Mandating CIBA.
Nat to suggest setting up sub-committee to FAPI to deal with BG needs. Two co-chairs. Dave Tonge from OIDF and another from BG.
Trying to move CIBA Core to final. There are a couple of issues that are being covered by PRs.
- Adding text for sender constrained token and push mode.
- New parameter for showing text on the consumption device. e.g., select a number from the following three.
- https://github.com/openid/modrna/issues/196
- https://github.com/openid/modrna/issues/177
- with relevant blog post: https://ritou.medium.com/binding-message-verification-and-candidate-list-parameter-in-oidc-ciba-90ffcefa6665
- Certs team is working on FAPI 1.0 Final test to go live at the end of this month. (Beta in one or two weeks.)
- Directed funding from Brazil for their profile.
- Simple Dynamic Client Registration being added.
- Stuart Demoed the current one.
- Discussed which files are to be processed automatically, and agreed.
- https://bitbucket.org/openid/fapi/pull-requests/266
- Addressing issue #396, related to #407
This introduces replace action into the GM specification and attempts to include security considerations with respect to permission propagation.
- Lukasz: If it is in fact merge, wouldn’t naming it “merge” make it more self-explanatory?
- Brian: The replace action text seems okay. But the security considerations seems overreaching.
- Dave: Use cases need to be collected.
- Ralph: Delete and Revoke have different connotations, esp. legally. In UK, the ownership of the grant rests on TPPs. TPP opinion needed.
- Dima: There are local requirements for Replace.
- Brian: Security concerns - not realistic to propagate the change in Grant to AT immediately.
- Separating the PR into two seems to be reasonable?
We had no time to discuss issues but Dave pointed out that new issue #411 should be considered re: HTTP signing.
- none
The call adjourned at 15:00 UTC