Re: [OAUTH-WG] Digest for DPoP

2021-02-19 Thread Brian Campbell
Hi Roberto, The SHMIP draft is in the OIDF's FAPI repository https://bitbucket.org/openid/fapi/src/master/ and mailing list is https://lists.openid.net/mailman/listinfo/openid-specs-fapi The GNA

Re: [OAUTH-WG] Token Mediating and session Information Backend For Frontend (TMI BFF)

2021-02-19 Thread Brian Campbell
Thanks Neil, Appreciate the insight and recommendations. I think we can incorporate that, more or less, into the next revision. One point to dig into just a bit more, you said that 'SameSite has a "GET-out clause" in the form of “lax”'. As I understand it, such a cookie would still only be sent on

Re: [OAUTH-WG] Digest for DPoP

2021-02-19 Thread Roberto Polli
Hi @all, I'm planning to read those I-D as they might be useful in a project, and I'm happy to provide feedback on digest usage. In general, when building protocols over HTTP it is necessary to take into account the semantics (eg. range requests, caching, ...) because reverse proxies, WAF and api

Re: [OAUTH-WG] Digest for DPoP

2021-02-19 Thread Brian Campbell
My inclination is to keep digest[1] out of the base DPoP document. I do believe that including it would add unneeded complexity to regular old DPoP (there are some subtleties around digest that make it more complicated than one might expect) and, from a design philosophy perspective, DPoP has alway

Re: [OAUTH-WG] Your opinion about draft-ideskog-assisted-token

2021-02-19 Thread Brian Campbell
Hi Adrian, I believe this work was presented briefly to the WG in London during IETF 101. As far as I can recall, the general reaction/thinking at that time was that the WG really should be working on a document about OAuth and single page applications (that may or may not include something like t

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Interims

2021-02-19 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT DTSTART:1

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-04-19

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-04-19 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: Identity Use Cases in Browser https://datatracker.ietf.org/doc/html/draft-bertocci-identity-in-browser-00 Information about remote partic

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-04-12

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-04-12 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: Security BCP https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics/ Information about remote participation: https://ietf.web

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-04-05

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-04-05 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: RAR https://datatracker.ietf.org/doc/draft-ietf-oauth-rar/ Information about remote participation: https://ietf.webex.com/ietf/j.php?MTI

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-03-29

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-03-29 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: TMI BFF https://tools.ietf.org/html/draft-bertocci-oauth2-tmi-bff-00 Information about remote participation: https://ietf.webex.com/iet

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-03-22

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-03-22 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: OAuth 2.1 https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/ Information about remote participation: https://ietf.webex.com/ietf/j.p

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2021-03-15

2021-02-19 Thread IESG Secretary
The Web Authorization Protocol (oauth) WG will hold a virtual interim meeting on 2021-03-15 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: DPoP https://datatracker.ietf.org/doc/draft-ietf-oauth-dpop/ Information about remote participation: https://ietf.webex.com/ietf/j.php?M