Skip to content

FAPI_Meeting_Notes_2024 02 28_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2024-02-28)

Agenda

The meeting was called to order at 14:05 UTC.

  • Attendees:
  • Regrets:
  • Adopted as is.
  • OFBR – continued high volume of FAPI re-certification requests to meet central bank mandates/milestones. Certification team is doing an excellent job in managing the increased volume.
  • OPIN – starting to see next phase of FAPI re-certifications
  • Chile – 18 months timeline

5.1.   PR 463 Fixes #641 - Update abbreviated terms

5.3.   PR 473 Fixes #664 Update clause reference in Note2

6.1.   #653 Reference PAR in 5.3.1.1 (12)

  • Resolved

6.2.   #658 Use of FAPI with mandatory MTLS

  • #658
  • Dima to create a PR this week

6.3.   #626 Add some more text to Introduction

  • #626
  • Nat to create a PR

6.4.   #648 Define requirements for OpenAPI FAPI securityScheme type

  • #648
  • There is no sensible way to express a security scheme in OpenAPI right now.
  • This ticket is suggesting to create a document so that it can be proposed to them.
  • This does not impact the spec so the spec can proceed independently.
  • Peter Stanley supported it, mentioning that OpenID Connect is a scheme there.

6.5.   #662 length of nonce tested in OP conformance tests

  • #662
  • In FAPI2, it is not the web server limit but the internal processing e.g. DB.
  • Supports for minimum values for AS on nonce (64) and state (512).
  • Some discussion on the corresponding client values.
  • We should discuss it over a PR.

6.6.   #639 Avoid "should be" and "shall be" where possible

  • #639
  • Make authorisation server and/or clients etc. as the subject of the sentence.
  • Dave is going to make a PR

6.7.   #630 Continuation of #607 -- Add some text to make the readers aware of the caveats.

n/a

The meeting adjourned at 15:04.

Clone this wiki locally