-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2024 07 31_Atlantic
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
Date: July 31, 2024
Participants: Dave Tonge, Dima Postnikov, Lukasz Jaromin, Joseph Heenan, and others
- The meeting started with a small group. Dave Tonge suggested starting with the usual agenda and asked participants to add their names in the chat for attendance records.
- Mike and Nat were absent. No updates were received from Mike on events.
- Dave Tonge shared the basic agenda and inquired if anyone had additional items to discuss. No further additions were made.
-
PR #509:
- Discussion on merging PR #509. There were some change requests made by Ralph and Mark, which Dima addressed.
- Lukasz had reservations about the value of some of the changes but agreed to discuss them.
- After further discussion, it was agreed to keep the current wording, and PR #509 was merged.
-
PR #496:
- Dave Tonge updated on PR #496, mentioning that changes were made to follow recommendations. He requested additional approvals for merging.
- Lukasz reviewed and approved the changes, noting that most changes involved reshuffling and aligning documents.
- Discussion on how the use of RAR (Rich Authorization Requests) is referenced in the spec. Lukasz and Dima debated the inclusion of RAR in the current specifications.
- It was decided to keep the RAR note in the current spec but to consider moving it to a more appropriate document in the future.
-
TLS 1.2 and BCP 195:
- A small PR was discussed to adjust the language related to the use of TLS 1.2 and its relation to BCP 195.
- The group agreed to remove the reference to TLS 1.2 specifically and keep the general recommendation.
-
FAPI 2 Formal Analysis:
- A suggestion was made to ensure the FAPI 2 formal analysis is referenced correctly throughout the document. Dave agreed to handle this.
-
Cyber Safety Review Board Report:
- Discussion on the Cyber Safety Review Board's recommendation related to key rotation and scope. Joseph highlighted the need for additional security considerations around these topics.
- It was agreed that the group would explore referencing existing best practices from NIST or similar organizations.
- The meeting concluded with the agreement to merge the discussed PRs and continue refining the specifications. Further work on implementation guidance and framework documents was noted as a priority.