-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 07 17_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date: 2024-07-17
- Location: Zoom
- Nat Sakimura
- Mike Leszcz
- Dima Postnikov
- Filip Skokan
- Lukasz Jaromin
- Imran Ulghar
- Dave Tonge
- Aaron Parecki
- Domingos Creado
- Ralph Bragg
- Mark Andrus
- Roll call and agenda review
- Vote on refresh token rotation
- Updates from Mike on OIDF events and outreach
- Review of open PRs and issues
- Discussion on security considerations for FAPI2
- Extensive discussion on options for handling refresh token rotation in FAPI2
- Three main options considered:
- Prohibit rotation completely
- Allow rotation but with specific semantics defined
- Soft limit on rotation, allowing exceptions but not defining specific semantics
- Consensus reached on Option 6
- Dima tasked with drafting specific language for the specification
- Concerns raised about impact on existing implementations and certification
- Debate on testability of different options
- Discussion on use cases for rotation (e.g. migration scenarios)
- Agreement that rotation should not be used for general security purposes
- Workshop planned for October 28th before IIW, details to be published in early August
- Recent meetings with CFPB and Open Banking Canada
- Continued engagement on FAPI1 vs FAPI2 questions
- Brief discussion on Issue 704 regarding security considerations
- Consensus to include security considerations in the main FAPI2 spec rather than a separate document
- Dima to draft specification language for refresh token rotation based on Option 6
- Work to continue on security considerations section for FAPI2 spec
Next week, same time