Wiki

Clone wiki

fapi / FAPI_Meeting_Notes_2019-05-29_Atlantic

FAPI WG Meeting Notes (2019-05-29)

Date & Time: 2019-05-29 14:00 UTC

Location: GoToMeeting https://global.gotomeeting.com/join/321819862

The meeting was called to order at 14:05 UTC.

1.   Roll Call

  • Attending:
    • Nat Sakimura (NRI)
    • Dave Tonge (Moneyhub)
    • Bjorn Hjelm (Verizon)
    • Brian Campbel (Ping)
    • Joseph Heanan (FinTech Labs)
    • Torsten Lodderstedt (YES)
    • Ralph Bragg (Radium)
  • Regrets:

3.   Issues

With regard to the removal of public client from the part 2, Dave created a pull request https://bitbucket.org/openid/fapi/pull-requests/106/first-attempt-at-removing-public-client/diff

Additionally, WG dealt with the following issues:

  • #169 - Add requirement for clients to verify scope value returned from the token endpoint
  • #173 - Mix-up mitigation (defense in depth)

Created two new issues:

  • #224: FAPI certification conformance profile definitions needed
  • #225: Remove references to OAuth Token Binding

3.1.   Next Call

  • Atlantic "Regular" call next week.

The meeting was adjourned at 15:05 UTC.

Updated