Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mediated vs Unmediated Logins #17

Open
johnwilander opened this issue Aug 24, 2020 · 6 comments
Open

Mediated vs Unmediated Logins #17

johnwilander opened this issue Aug 24, 2020 · 6 comments

Comments

@johnwilander
Copy link
Collaborator

"Managed logins" is useful way of expressing that the browser was involved in the user just logging in.

Likewise, "Unmanaged logins" can codify all the cases where the browser is not involved and just get the signal from the website that the user is logged in.

We propose this spec uses the terms managed and unmanaged logins for this purpose.

@johnwilander johnwilander self-assigned this Aug 24, 2020
@johnwilander johnwilander added the agenda+ Request to add this issue to the agenda of our next telcon or F2F label Aug 24, 2020
@samuelweiler
Copy link

I like browser-managed.

@timcappalli
Copy link
Member

Managed is a loaded term. I would +1 "Browser Mediated Login" from the call today.

@ajknox
Copy link

ajknox commented Aug 28, 2020

"Browser Mediated Login"
vs.
"Unmediated Login"

You could add other mediation channels to the terminology if it ever became germane -- I could imagine special discussion for out-of-band, 2fac, and PAKE.

@melanierichards melanierichards removed the agenda+ Request to add this issue to the agenda of our next telcon or F2F label Sep 9, 2020
@melanierichards
Copy link
Collaborator

Removed agenda+, seems like we have good consensus on "browser mediated login". Can raise for group review again when we make related edits to spec text.

@gffletch
Copy link

gffletch commented Sep 10, 2020

Please note that the browser can "mediate" a login flow without being directly involved in the presentation of credentials to the authentication endpoint. For me "mediate" means that the browser is directly involved in tracking/managing the login/sign-up flows regardless of how authentication happens. What about something like "Browser Mediated Credentials" as that is more specifically what we are describing (the browser is involved in presenting the authentication credentials; i.e. webauthn and/or password managers).

Then we can use "browser mediated login" to represent when the browser is involved in managing the login flow even if authentication is completely out of band (e.g. QR code scan, push notification, etc).

@samuelgoto
Copy link

FWIW, I've been using "mediated login" [1] in WebID, but I'd be happy to change and converge on terminology if you all arrive at something else.

[1] https://github.com/WICG/WebID/blob/main/navigations.md#the-mediation-oriented-variation

@johnwilander johnwilander changed the title Managed vs Unmanaged Logins Mediated vs Unmediated Logins May 11, 2021
@melanierichards melanierichards added the agenda+F2F Request to add this issue or PR to the agenda for our upcoming F2F. label May 11, 2021
@erik-anderson erik-anderson removed the agenda+F2F Request to add this issue or PR to the agenda for our upcoming F2F. label Jun 7, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

8 participants