-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 03 19_Atlantic
- Date: 2025-03-19 14:00 UTC
- Location: Zoom
- Nat Sakimura (Chair)
- Dave Tonge
- Dima Postnikov
- George Fletcher
- Filip Skokan
- Joe DeCock
- Peter Stanley
- Jake Fenley (Observer)
- Kosuke Koiwai
- Peter Wallach
- Bjorn Hjelm
- Hideki Ikeda
Meeting began with a roll call via chat, followed by agenda adoption. Jake Fenley joined as an observer from Dave Tonge's team (IPR contribution pending).
Upcoming events were noted:
- IETF in Bangkok (March 15-21)
- OIDF Workshop prior to IIW at Google in Mountain View (April 7)
- DCP Working Group meeting prior to the workshop at Google
- IIW (April 8-10)
- RSA 2025 (April 28-May 1) in San Francisco
- EIC in Berlin (May 6-9)
- ID4Africa in Addis Ababa (May 20-23)
- Identiverse in Las Vegas (June 3-6)
Dima Postnikov reported on two blog posts being prepared for publication:
- A post describing differences between FAPI 2 Implementers Draft 2 and FAPI 2 Final
- A post explaining Grant Management and RAR in relation to FAPI authorization
Dima also noted that voting had opened for the DCP Working Group's HAIP profile and encouraged members to vote: https://openid.net/foundation/members/polls/355
George Fletcher mentioned an active thread in the OAuth mailing list regarding step-up authentication with RAR, suggesting members keep an eye on this discussion.
Dave Tonge presented a PR for the message signing final draft that:
- Adds security analysis link
- Updates references
- Makes editorial changes to prepare for publication
- Adds line in the intro: "is for has been formally analyzed with reference for its security and non-repudiation properties"
The PR was approved by Nat during the call.
Audience PR for CIBA (#529)
Discussion on Joe DeCock's CIBA audience PR:
- The group is waiting on changes to the underlying specs
- The current plan is to wait until FAPI 1 errata is completed
- Joe indicated he was open to either approach (explicit mention vs. relying on underlying specs)
- No urgent action is needed as CIBA is not widely used currently
typ in Request Header (Issue #693)
- Discussion about conformance testing for
typin request - Filip Skokan reviewed the code and noted it only checks if the header is present and if the value is "jwt"
- The code doesn't handle prefixes properly
- Issue to remain open as the PR didn't fully address the requirements
Private Key JWT Audience Restrictions (Issue #714)
- Filip Skokan reported waiting for resolution on private key JWT audience restrictions
- Indicated there are tests failing when authorization servers enforce new value
- Clash between updating test suite for new guidance vs. allowing OPs to reject non-compliant values
- Filip expressed concern about the lack of progress on both this issue and FAPI 2 final tests
Dave Tonge proposed opening a new issue to get a timeline for the FAPI 2 final test suite.
The group discussed items to include in a new Implementation and Deployment Considerations document:
AS Rejecting Suspicious Requests (Issue #598)
- Discussion about authorization servers rejecting requests with suspicious state/nonce parameters (e.g., script tags)
- Agreement that AS can reject suspicious requests but shouldn't wholesale block certain characters
- Decided to include guidance on this in the document, with a short paragraph in security considerations
UX Guidelines and Consent (Issue #429)
- Discussion about the importance of user experience and proper user consent
- Agreed such guidelines should be ecosystem-specific rather than part of FAPI core specs
- Peter Stanley offered to share UK Open Banking's customer experience checklist and process
x-fapi Headers (Issue #282)
- Discussion about the use of X-FAPI headers that were in FAPI 1 but removed from FAPI 2
- Dima noted that while most headers aren't properly used, the X-FAPI-Interaction-ID is valuable for debugging and tracking
- Discussion about whether to standardize headers across ecosystems
- Concerns about IP address disclosure and customer presence indications
- Agreement to poll existing ecosystems about what headers they find useful
- Note that x- prefix convention is outdated
Error Messages (Issue #434)
- Discussion about appropriate error messages, particularly for unrecoverable errors
- Certification team looking for guidance on acceptable error messages
- Agreement that for unrecoverable errors (like invalid redirect URI), the message should inform users it's not recoverable
- Some suggestion that "please try again later" might be appropriate for errors that could be fixed by configuration
- Group to discuss more with Joseph in a future meeting
- Dave Tonge to open an issue about getting a timeline for FAPI 2 final test suite
- Dave to begin work on the Implementation and Deployment Considerations document
- Peter Stanley to share UK Open Banking's customer experience guidelines process
- Group to consult with Joseph on error message guidelines
No other business was raised. The meeting adjourned at the top of the hour.