Skip to content

FAPI_Meeting_Notes_2024 01 24_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2024-01-24)

Agenda

The meeting was called to order at 14:04 UTC.

  • Attendees: Daniel Ffett, Nat Sakimura, Peter Stanley, Robert Gallagher, Joseph Heenan, Peter Wallach, Kosuke Koiwai, George Fletcher, Mark Andrus, Dave Tonge, Filip Skokan, Bjorn Hjelm
  • Regrets:
  • Adopted as is.

https://www.openid.or.jp/summit/2024/en/

Friday, January 19, 2024, 10:00 - 18:00

Over 300 people attended with standing room only. Generally speaking, it was well received. For FAPI related topics, there was a speech by Nubank representative.

Submissions are open.

Deadline: 11th February for early submissions.

https://oauth.secworkshop.events/osw2024

Next deadline is March 10 for submissions

The call for presentation closes on Jan 31.

Certification rolling in.

An inquiry came in.

  • PR #455
  • Added the mapping table of attacker numbers in security analysis to new attacker numbers
  • Merged
  • PR #454
  • Removed text regarding anti-virus software
  • Changed enforcement of one-time use to at the point of authentication
  • George approved the suggested language.
  • Joseph asked if this was enough to generate a warning in the certification.
  • No pushback.
  • PR #457
  • Accepted
  • PR #458
  • Filip expects more feedback from ecosystems as this is a significant change.
  • Language similar to current version but Conformance suite does not have tests yet so uncertainty remains on how new language will affect ecosystems
  • Avoids problem by having clients sidestep the problem
  • Filip created an issue for the Conformance suite
  • Not aware of any ecosystems relying on current behavior
  • Doesn’t affect UK, Need to check with Brazil (Ralph) and AU (Dima)

5.5.   PR 459 Fixes #633 - Author name of Normative reference ISODIR2 is wrong

  • PR #459
  • Accepted

5.6.   PR 460 Fixes #631 - Subclause 5.3 has a hanging paragraph

  • PR #460
  • Some subclauses with be renumbered
  • ISO does not allow hanging paragraphs
  • Accepted

5.7.   PR 461 Fixes #636 - The first paragraph of the Normative reference shall be as provided in ISODIR2

  • PR #461
  • Replaced with standard ISO text
  • Accepted

5.8.   PR 462 Fixes #637 - ISO29100 and ISO29134 is not in the reference

  • PR #462
  • Accepted

5.9.   PR 463 Fixes #641 - Update abbreviated terms

  • PR #463
  • Some of the abbreviations like "AS" has been removed from the main text so it should also be removed from the abbreviations.
  • Similarly, we should avoid "OP", “RS”.
  • New issue will be created for removing those abbreviations
  • PR #464
  • Accepted

5.11.   PR 465 Addresses #635 - Following documents are not normatively required

  • PR #465
  • Accepted
  • Need merge with other Daniel’s PR changing RAR to RFC

5.12.   PR 466 Addresses #660 - inconsistent capitalization

  • PR #466
  • We need to check "client" is always used in the sense of OAuth client and if that is the case, add it to the terms and definition.
  • ISO only allows capitalization at the start of sentences and proper names.
  • Capitalization of keywords does not translate well to languages without capitalization (e.g. Japanese)

5.13.   PR 467 fixes #624 - remove unnecessary normative references

  • PR #467
  • Accepted
  • #661
  • Callers agreed to add Joseph to the list of authors in FAPI2.

n/a

The meeting adjourned at 14:59.

Clone this wiki locally