-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2023 03 15_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date & Time: 2023-03-15T14:00Z
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
- Self: https://github.com/openid/fapi/wiki/FAPI_Meeting_Notes_2023-03-15_Atlantic
Agenda
The meeting was called to order at 14:02 UTC.
- Attending: Nat, Gail, Joseph, Mike, Tim, Aaron, Brian, Daniel, Dave, Filip, Geroge, Justin, Marcus, Kosuke, Pedram, Kelley, Pieter, Dima
- Regrets: Chris
- Guest:
- Adopted as presented as draft agenda.
- Scope is FAPI CIBA, Dynamic Client Registration (including Australian variant) and FAPI 2.0 Message Signing (including JARM, JAR. jIR, HttpSiG)
- Meeting at 8 AM CET.
- Workshop on 1 PM Apr. 17. Details to be published this week.
- n/a
- No material updates.
- Certification request continues to come in.
- KSA FAPI Profile Framework is not publicly available yet. Quality control is being performed.
- This caused problems for parties that wanted to comply with the profile.
- Good news is that it seems it is possible to publish FAPI-specific components at openid.net. It will be confirmed shortly.
- Package was sent to the foundation secretary.
- Question was raised whether the title should have "Draft" or "Implementer's draft"
- It should be "Draft" because it has not been voted on.
- The draft will be updated and sent to the foundation secretary again.
- Editors, please make sure that your draft has "draft" or "Implementers draft #" in the title.
- Also, please make sure to put warning text.
- Apart from one PR that we are parking until HTTP signature is settled, there is no standing PR.
- #579
- https://github.com/openid/fapi/issues/579
- Normative sentences should not go into Note.
- We wanted to leave options open for CIBA and Token Endpoint.
- #577
- https://github.com/openid/fapi/issues/577
- Brian's wording was discussed.
- It was pointed out that while it is rejecting the response types quoted, it does not others.
- Adding parameters (esp. tokens) would create a new authentication protocol and nullify the security analysis.
- In view of this, it was suggested to lock it down to response_type=code while making it conditional that future extensions, such as CIBA, can be made. (They need a fresh security analysis and we are doing that in FAPI2 Workpackate 2 sponsored by the AU government.)
- Filip came up with wording that sounded reasonable. He will put it in this ticket.
- none
The call adjourned at 14:59