Skip to content

FAPI_Meeting_Notes_2024 11 27_Atlantic

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Meeting Notes - November 27, 2024

Participants

  • Mike Leszcz (OIDF)
  • Kosuke Koiwai
  • Hideki Ikeda
  • Joseph Heenan (OIDF & Authlete)
  • George Fletcher
  • Nat Sakimura
  • Dima Postnikov
  • Peter Stanley (OBL)
  • Dave Tonge
  • Filip Skokan
  • Daniel Fett
  • Axel Nennker (DT)

1. Events Updates (Mike L.)

  • Gartner Identity & Access Management Summit (December 9-11, 2024)

    • In Dallas, Texas
    • OIDF presentation and Shared Signals demos planned
    • Details available on OIDF web and Google calendars
  • OAuth Security Workshop 2025 (February 26-28, 2025)

2. External Organizations Update (Mike L.)

  • Completed workshop for UAE TTPs last week
    • Overview of OIDF and FAPI spec
    • Demonstration of UAE FAPI profile conformance tests
    • ~45 participants from 15-20 organizations
    • Recording and deck published to OIDF website
    • https://openid.net/presentations-media/

3. Technical Discussion

DPoP Error Code Discussion

  • Question raised about error codes when clients don't send required DPoP requests
  • Consensus that "invalid_request" is appropriate error code
  • Discussion of T-Mobile US requiring sender-constrained tokens for new APIs
  • Noted that some implementations may need to support both DPoP and non-DPoP flows
  • Conformance suite returns invalid_grant but that could be due to the use of PAR

4. Pull Requests Review

Merged PRs:

  1. PR #523 - IANA registration section updates
  2. PR #524 - JAR errata fixes
  3. PR #525 - Name spelling correction

PR #522 Discussion:

  • Extended discussion on client requirements
  • Concerns about implementation complexity during transition period
  • Agreement to merge based on working group consensus despite not being unanimous
  • Decision to document reasoning in PR comments

PR #519 - initial work on creating separate http signing spec

copies current text regarding HTTP signatures into new draft

5. FAPI Implementation Discussions

FAPI 2 Final Review Process

  • Agreement to restart the public review process
  • Message Signing spec to be handled separately
  • One PR remaining for HTTP signatures separation

FAPI 1.0 Maintenance

  • Discussion of potential FAPI 1.1 vs errata approach for security updates
  • Waiting for clarification on what changes can be included in errata
  • Need to balance supporting existing ecosystems while encouraging FAPI 2 adoption
  • Consideration of certification implications

6. Action Items

  1. Dave to document PR #522 decision reasoning and merge
  2. Nat to check with Mike Jones regarding precedent for security changes in errata
  3. Dave to verify and close remaining issue on FAPI 2 attacker model
  4. Continue work on separating HTTP signatures from message signing spec

Next Meeting

Next call will be December 4, 2024.

Clone this wiki locally