Wiki

Clone wiki

fapi / FAPI_Meeting_Notes_2024-06-19_Atlantic

FAPI WG Agenda & Meeting Notes (2024-06-19)

The meeting was called to order at 14:05 UTC.

1.   Roll Call (Nat)

  • Attendees:
  • Regrets:

5.   PRs (Dave)

5.3.   496 - issue-694 readability of refresh token rotation clause

5.4.   502 - access token privilege restriction

5.5.   503 - client impersonation

5.6.   504 - initial attempt at CORS wording

6.   Issues (Dave)

6.1.   699 - FAPI 2 vs. Security BCP Gap Analysis

6.1.1.   End-to-end TLS recommendation

  • It was pointed out that it is not realistic to demand it in the current environment.
  • It is not testable, either.

6.1.2.   In-Browser communication

  • Different views expressed whether to restrict or not.
  • Perhaps a security consideration that defers to the Security BCP?

7.   AOB

  • No other business raised

The meeting adjourned at 15:01.

Updated