Skip to content

FAPI_Meeting_Notes_2025 03 20_Pacific

Nat Sakimura edited this page Jul 10, 2026 · 1 revision

FAPI WG Agenda & Meeting Notes (2025-03-20)

The meeting was called to order at 00:00 UTC.

  • Attendees: Mark, Dima, Anoop
  • Regrets:
  • ISO/IEC JTC 1/SC 27/WG5: March 10-15, 2025 in Fairfax
  • ISO/IEC JTC 1/SC 27: March 17-18, 2025 in Fairfax
  • MOSIP Connect: March 11-13 in Philippines
  • IETF Bangkok: March 15-21
  • OIDF Workshop prior to IIW: April 7
  • DCP Working Group meeting prior to the workshop at Google
  • IIW Spring 2025: April 8-10
  • OpenID Federation Interop Event, April 28-30, 2025
  • RSA 2025 (April 28-May 1) in San Francisco
  • EIC in Berlin (May 6-9)
  • Identiverse in Las Vegas (June 3-6)

OIDF calendar on website is current: https://openid.net/calendar/

# Blog Posts Dima Postnikov reported on two blog posts being prepared for publication:

  1. A post describing differences between FAPI 2 Implementers Draft 2 and FAPI 2 Final
  2. A post explaining Grant Management and RAR in relation to FAPI authorization

https://www.linkedin.com/posts/openid-foundation_standardized-fine-grained-authorization-activity-7308474238825361408-p27m?utm_source=share&utm_medium=member_ios&rcm=ACoAAAA9W8kB2il3b4X1KAFSwb9w-mstylRtMpQ

https://www.linkedin.com/posts/openid-foundation_implementers-guide-fapi-20-final-vs-implementer-activity-7308621278104412160-PcNH?utm_source=share&utm_medium=member_ios&rcm=ACoAAAA9W8kB2il3b4X1KAFSwb9w-mstylRtMpQ

# DCP WG: Voting on HAIP Dima also noted that voting had opened for the DCP Working Group's HAIP profile and encouraged members to vote: https://openid.net/foundation/members/polls/355

# OAuth WG: Step-Up Authentication George Fletcher mentioned an active thread in the OAuth mailing list regarding step-up authentication with RAR, suggesting members keep an eye on this discussion.

Conformance Testing

  • typ in Request Header Issue #693
    • PR is open as it did not address the requirement.
    • Code looks for header to be present with value "jwt" and also it doesn't handle prefixes.
  • Private Key JWT Audience Restrictions (Issue #714)
    • Filip Skokan reported waiting for resolution on private key JWT audience restrictions
    • Indicated there are tests failing when authorization servers enforce new value
    • Clash between updating test suite for new guidance vs. allowing OPs to reject non-compliant values
    • Filip expressed concern about the lack of progress on both this issue and FAPI 2 final tests

Implementation and Deployment Considerations Document Issues

  • AS Rejecting Suspicious Requests (Issue #598)
    • Discussion about authorization servers rejecting requests with suspicious state/nonce parameters (e.g., script tags)
    • Agreement that AS can reject suspicious requests but shouldn't wholesale block certain characters
    • Decided to include guidance on this in the document, with a short paragraph in security considerations
  • UX Guidelines and Consent (Issue #429)
    • Agreed such guidelines should be ecosystem-specific rather than part of FAPI core specs
  • x-fapi Headers (Issue #282)
    • Discussion about the use of X-FAPI headers that were in FAPI 1 but removed from FAPI 2
    • Dima noted that while most headers aren't properly used, the X-FAPI-Interaction-ID is valuable for debugging and tracking.
    • Note that x- prefix convention is outdated
  • Error Messages (Issue #434)
    • Discussion about appropriate error messages, particularly for unrecoverable errors
    • Certification team looking for guidance on acceptable error messages.
    • Need further discussion

Next call will be an Atlantic Call.

Clone this wiki locally