-
Notifications
You must be signed in to change notification settings - Fork 0
FAPI_Meeting_Notes_2025 03 20_Pacific
Nat Sakimura edited this page Jul 10, 2026
·
1 revision
- Date & Time: 2025-03-21 01:00 UTC
- Location: https://zoom.us/j/97456084642?pwd=bTRFVzk4ZmlRK1M3bEprRlN5c3JFZz09
Agenda
The meeting was called to order at 00:00 UTC.
- Attendees: Mark, Dima, Anoop
- Regrets:
- ISO/IEC JTC 1/SC 27/WG5: March 10-15, 2025 in Fairfax
- ISO/IEC JTC 1/SC 27: March 17-18, 2025 in Fairfax
- MOSIP Connect: March 11-13 in Philippines
- IETF Bangkok: March 15-21
- OIDF Workshop prior to IIW: April 7
- DCP Working Group meeting prior to the workshop at Google
- IIW Spring 2025: April 8-10
- OpenID Federation Interop Event, April 28-30, 2025
- RSA 2025 (April 28-May 1) in San Francisco
- EIC in Berlin (May 6-9)
- Identiverse in Las Vegas (June 3-6)
OIDF calendar on website is current: https://openid.net/calendar/
# Blog Posts Dima Postnikov reported on two blog posts being prepared for publication:
- A post describing differences between FAPI 2 Implementers Draft 2 and FAPI 2 Final
- A post explaining Grant Management and RAR in relation to FAPI authorization
# DCP WG: Voting on HAIP Dima also noted that voting had opened for the DCP Working Group's HAIP profile and encouraged members to vote: https://openid.net/foundation/members/polls/355
# OAuth WG: Step-Up Authentication George Fletcher mentioned an active thread in the OAuth mailing list regarding step-up authentication with RAR, suggesting members keep an eye on this discussion.
Conformance Testing
- typ in Request Header Issue #693
-
- PR is open as it did not address the requirement.
-
- Code looks for header to be present with value "jwt" and also it doesn't handle prefixes.
- Private Key JWT Audience Restrictions (Issue #714)
-
- Filip Skokan reported waiting for resolution on private key JWT audience restrictions
-
- Indicated there are tests failing when authorization servers enforce new value
-
- Clash between updating test suite for new guidance vs. allowing OPs to reject non-compliant values
-
- Filip expressed concern about the lack of progress on both this issue and FAPI 2 final tests
Implementation and Deployment Considerations Document Issues
- AS Rejecting Suspicious Requests (Issue #598)
-
- Discussion about authorization servers rejecting requests with suspicious state/nonce parameters (e.g., script tags)
-
- Agreement that AS can reject suspicious requests but shouldn't wholesale block certain characters
-
- Decided to include guidance on this in the document, with a short paragraph in security considerations
- UX Guidelines and Consent (Issue #429)
-
- Agreed such guidelines should be ecosystem-specific rather than part of FAPI core specs
- x-fapi Headers (Issue #282)
-
- Discussion about the use of X-FAPI headers that were in FAPI 1 but removed from FAPI 2
-
- Dima noted that while most headers aren't properly used, the X-FAPI-Interaction-ID is valuable for debugging and tracking.
-
- Note that x- prefix convention is outdated
- Error Messages (Issue #434)
-
- Discussion about appropriate error messages, particularly for unrecoverable errors
-
- Certification team looking for guidance on acceptable error messages.
-
- Need further discussion
Next call will be an Atlantic Call.