Re: [art] Artart last call partial review of draft-ietf-oauth-iss-auth-resp-02

Francesca Palombini <francesca.palombini@ericsson.com> Mon, 29 November 2021 21:23 UTC

Return-Path: <francesca.palombini@ericsson.com>
X-Original-To: art@ietfa.amsl.com
Delivered-To: art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D723C3A0C9E for <art@ietfa.amsl.com>; Mon, 29 Nov 2021 13:23:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.801
X-Spam-Level:
X-Spam-Status: No, score=-2.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.701, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H8PDZKqUD94c for <art@ietfa.amsl.com>; Mon, 29 Nov 2021 13:23:46 -0800 (PST)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-eopbgr70078.outbound.protection.outlook.com [40.107.7.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E6C923A0B85 for <art@ietf.org>; Mon, 29 Nov 2021 13:23:30 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LGj7dy4NHi3QoW+xyn80uSFuJeFvv9rI4fVYi8BZmLvCa/6UcoOGFM4RWAgP+PTg7gYjU9P71KZxUeTNkjjecJo08aeVdEtbIoPkDaVypzGLS/sJTlsJWz7BcmSD45jdEkHz24+GSTgQzqkl/meBVb+1k/j76GNfD9CqL7zbUZbWRCaUkEELrwW/GyTYEGCMbgp8S0lazClkNXzW/YtkYg+iVlHxsz+BQaPq6mMBRZPAIyAr6EuRmJDkcAJ7SG+pwI5akByVZa0NNOTYZedi5Mea4kUbasIauQwSY6GbxH8/WVjEB4N+UlygjS2oLjVKlMZnYG6RR/8Cqatu5X4SYQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xXVqAtp4hL+CywvIJEKmRvSng4d3FJPmO0Nca8x4ic0=; b=OQ9U6EYHanEEHMa+UvgK8oQGHGRJOrUdifkbsjJAMZSU2Sn6n15KAuqAjLo8w7UgpT9hYv0K7uB0z5nPxEq59ElgVLBPAUVR+aM1TIjmQ+6lwYE3/1SBw37mQjNrJpI9zy87O60HPVhpZYrHzQxKEVJgMOXnwP3JMu1urQ6s8XbNZuvLG3MwxG6hRoSLszczs2t15iKyFC3uD4WPtgpZGrK5YDod3HTEdrAE2KlxFCqx13kWEKX56lCn4/lF4wJMAgR102SfXD3jbKEBkbZ+WYTjP119JTtICRAARUZnt7DcuJN81+tyaC/Jbt8lmUEar8GlXqXyD+KGCNmvDbxMzQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xXVqAtp4hL+CywvIJEKmRvSng4d3FJPmO0Nca8x4ic0=; b=sHs6plwtAAqzKaiJ2Q2fH5Jv4Okr0rDB5sZF5gOw1vcBclN+kH1BVDVVYAYrLw4X3HG6owjCI4hW5ojy0MJm0i7kEDvRIP/IjKQOQiUQuL8lO3v5gyfb2bgc02zr12My+TOk7ljX4qzTJ+4V0JdRfmlFxr4bgPY+37jgZhosq+s=
Received: from HE1PR07MB4217.eurprd07.prod.outlook.com (2603:10a6:7:96::33) by HE1PR0702MB3771.eurprd07.prod.outlook.com (2603:10a6:7:88::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4755.9; Mon, 29 Nov 2021 21:23:28 +0000
Received: from HE1PR07MB4217.eurprd07.prod.outlook.com ([fe80::cdd0:1e2:cd0b:790f]) by HE1PR07MB4217.eurprd07.prod.outlook.com ([fe80::cdd0:1e2:cd0b:790f%7]) with mapi id 15.20.4755.011; Mon, 29 Nov 2021 21:23:28 +0000
From: Francesca Palombini <francesca.palombini@ericsson.com>
To: Julian Reschke <julian.reschke@gmx.de>, "art@ietf.org" <art@ietf.org>
Thread-Topic: [art] Artart last call partial review of draft-ietf-oauth-iss-auth-resp-02
Thread-Index: AQHX2jFoXHvQQfwQ00SZIb4ZDZNp86wE1yQAgBZCthg=
Date: Mon, 29 Nov 2021 21:23:28 +0000
Message-ID: <HE1PR07MB421720FC5A7EB4A366631E1D98669@HE1PR07MB4217.eurprd07.prod.outlook.com>
References: <163576279118.23946.14747101192871915313@ietfa.amsl.com> <7c515322-b19f-a1a6-e36a-100ff8d8ef58@hackmanit.de> <148562e9-4eaf-dc55-3c19-b822e0b430ec@gmx.de>
In-Reply-To: <148562e9-4eaf-dc55-3c19-b822e0b430ec@gmx.de>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 8caf54a6-2c40-4138-d0a5-08d9b37e7c4a
x-ms-traffictypediagnostic: HE1PR0702MB3771:
x-microsoft-antispam-prvs: <HE1PR0702MB3771FB565400030EB5B05A6598669@HE1PR0702MB3771.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: kHxnS6sm51udDeikwDqw4ZhU5Tlr2bYP0proItGteE5Vbd36759H5sJVdFji5nXzoCBKBzlliz5mq8LwkqMq2gCyjrvMFzC5m3S98RzQqghXv1NT1mFgPwhdPs5nhAsV0rQiQtu69uiINMWpNNo1LwXHTB1FixLaMu9/C8AzdXjV7xh9rnLNjaU+UPOn53JEU3Ghh4VeCK/PLGzyAea1KGs5bNkdN9vhUpt6yWn1UxzG20wmSQE6dn/HMxGl/diXhCMH647XKPpcP3f0UdQtOayG5m6vXoT/+OqtGZjYiXbjiq7RzoTG4k0kOoz/Cxb30HZ2ITqo/WIzHZgAmCcCAeGugh7xkoXavhPbF47Whi52PeURohzDmSfhr1cnsTf4t5NJMQ9y3tFB6Oz1Lpncr7Nn257vESSIRe5S3zB2pODXl0+Ar503TCU2bImKIFrfGaB+GA593cKt1hvcOcE1PhQ1UWCAtErNmybd1xXtYlgiGZnfLAkkE9stpVKKcGcgdVTQKKl8ccx59cJ5A9fW8W34qTuIODzQqwOSCG+E2HklmTFao4AoTzRDJm7WQJskAh16sSFWtcUu0iWWpVFXC5mxqPWByCURbtD2qUHhVmEquGuBRp4OWmmsh+KyV1l1Ms27oK+CErPKzDf9ViyBqUwNAf7jPpIB7b/CIG5tUY6S0X4vMxjLyvdN+oCovwlojzlSzBaLz1bFVvoOPqRAlNCKAralDb5+PzIMDqbM0Khmxot4vz/Afv5t2ulJe5A/jmZ1+6K2lgmrZ8wX5G135yKeRxd0neCjVo/VLCirWM0=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR07MB4217.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(52536014)(7696005)(2906002)(9686003)(82960400001)(5660300002)(55016003)(71200400001)(122000001)(166002)(6506007)(8936002)(8676002)(38070700005)(966005)(76116006)(110136005)(66946007)(66476007)(66556008)(64756008)(66446008)(508600001)(316002)(33656002)(38100700002)(44832011)(186003)(83380400001)(53546011)(86362001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 2
x-ms-exchange-antispam-messagedata-0: +lVOZ5JysCB70f1ynsgNuEpR0NVEU9PTBDAfYHxEuDO7nzWrwCIJlcHD1fHdUezs3kjUhiuBv0/UqeGgjTby3tofZGsEmSFRWXD+EC+NKPzlL5C1OlGZMz2ihppIzZ9E3xObrXRgvKSumqQ+gZXfdT3nTkOQOYMTN0knY3080WsX91oNtlh8Z/bS9F20Px2afu96AMGto1ZtkVM/uiDvuo5ZsuP2GqMmJ5K/5tSOMbAFnRSuP3ygsegAPs17EH1gcoABlP8lg0ObovyH+GZ9GfzgzRYotsQywSq0OSp4W9XxdYbsR1ZHKxtWRd4gMuGMy6hJCbD/jUhhKGz2GcFurJxe9XuEsZM+kV/0y8LlS4OVJJLKvx6h27dHYkmeJY2JILh/MTnzf+D2h6vfk1eoywmQfV9etxYvO/NlVirhdFhS50vwSTJA5NrmEZ8jyTWeGc/O8/gz2dxVhHHiO99e2Z7opR2SaMqQBwNdkFNdwPLvWyakJsjm6xd5CVpjt2H8eiuIygwdwnM+z1UhPhy9bl4DC/W9+4v9pshHDVywwPcfjK75RvAllZUfybdoiSL8vqKy8iNTiaBcObBda4QDX9ONHpGpWvrGeVyC2IBFQRj5JgG4PUCmaGj/all+tvp3nSQBmEuJqy61GDF5HxpBGXyU0rx1Ltubr/ASQR9RX2t1E9fg59JXu8aJTgGI2AKQzfA5ec2NQavn4tPHnpQa0My0cn6cBbXeF9JYOhqeOBD9sqSUEQZRC5vRBT7mUF/pAKz1E0nck3mMANWP34Rp6nKorboX0jxlAXNCNSK3KIZTTsDUGXIPtbeEhXkMr9+WGcCfHCn/FHUvvCRprtBx3EyjC2KYitxKTK2sHWXd43e6IDWEQvhChxbQSFBoI/P1dJoaQcac1tK1goy38w0xMabOsA7T56F0iOX5hZMrYC07ESUA1ZCco9PdNz+ZCq2Q3Sv5LPCXJe7fRLDjY+lam8O8AA3ns19s9MldDRVA3eT5+frnjK7cJ6Zpi7Sowh5D7atWE1kXRKBu3zWQjL9G/Homtdu9S0FnvgZZosVigguW9xVVzew2qfAQgDphO5wuARv6FSmVSY+zX49fAOj1AKeld9uCipwO2GQWZwuQ7ilmB57xAAk7QFzvkhrJoteymx0YX8vllflyRfVTtiGxfq05KZ6Mu3q9F/Ei7hqDwNHcsPQcAUJX2wGX9LIN7y9VhI+sYqeGi9FzmGiBZaflx413GXBWGramZjdZG+jGgkYlo5PhfcsUiSx9+1n8U70cRt+iTGIw9kA3IekmvTFTlyi/H12CIhxo4Fw2nju/Yl7pYZrVR8yGSxILbd/gJKO85fi8uFSgoovM1lz7EUDtaueeZljAT7fLrlBJ3Edo9rWRXK5CGx+YiOWUBr9r0CfmtPmZkbjQpKH0hGJCWxuctvrDId40rMMDF3WJJuznbauAIuSV6JtsCWFCuHKGP9bOhkZwC2TWPWwUVCEhQJ7V+bgeQlXCF/IH/Ui452RxZstZjQR8cUVg2y58ZHeJkwGat5eRfKIzDgyCnTgh+1ZaM7lWHrGx0SyaCxtqcMRYV9cl9J7bqbTOQDjS884CKchbyKcb24qDz49qP87ARNDo5aBn0hyhlVwFaox6zXGZRvfJQdqsXJt2Mlm/JfScednlQDVxJn8Sum8lrbJfux/2+j0aTIWGC9EBM2czfkyjA18kSM8agxz8uz1CNV2RIs3aSWUES3Zu6MHhkj5Ilm9Kp1m88wzzaUcy8wX+W0My7gf+Xb6xbwkrL8zbtHlrVnIT5jg+uZNX
x-ms-exchange-antispam-messagedata-1: LPK5yoqet0HgMPk73VUozAQS0W9Lyvlt6bE=
Content-Type: multipart/alternative; boundary="_000_HE1PR07MB421720FC5A7EB4A366631E1D98669HE1PR07MB4217eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR07MB4217.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8caf54a6-2c40-4138-d0a5-08d9b37e7c4a
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Nov 2021 21:23:28.0885 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: qhc833CB4VPpQSTyRv6FL1UMjjTe2bnUppB8Jy5YRPuEopoPLZTnCHAGx+NIk/yZJUEFgrnwoCQHTziMVBPIXEOVJY6HmvQGo5bVf/sMAaSbShjxYfJhj0t0TUqZCFu7
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0702MB3771
Archived-At: <https://mailarchive.ietf.org/arch/msg/art/nrJUl8F0nUxlsqa_ParKUmaV2xc>
Subject: Re: [art] Artart last call partial review of draft-ietf-oauth-iss-auth-resp-02
X-BeenThere: art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/art>, <mailto:art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art/>
List-Post: <mailto:art@ietf.org>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/art>, <mailto:art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Nov 2021 21:23:55 -0000

Julian: thank you very much for this review! I balloted DISCUSS for an IANA issue I found.

Francesca

From: art <art-bounces@ietf.org> on behalf of Julian Reschke <julian.reschke@gmx.de>
Date: Monday, 15 November 2021 at 18:25
To: art@ietf.org <art@ietf.org>
Subject: Re: [art] Artart last call partial review of draft-ietf-oauth-iss-auth-resp-02
Am 15.11.2021 um 15:58 schrieb Karsten Meyer zu Selhausen:
> ...
>> Major issues:
>>
>> 2.4
>>
>> "Clients MUST compare the extracted and URL-decoded value to the issuer
>> identifier of the authorization server where the authorization request was sent
>> to."
>>
>> I'm not sure that "URL-decoded" is correct with respect to decoding query
>> parameters. Consider URLs containing "+" or "=". You probably need the encoding
>> rules for application/x-www-form-urlencoded instead.
> Good point. We changed the text to refer to
> application/x-www-form-urlencoded.

You may also want to add an example where the difference matters (such
as when the URI contains a plus sign).

>> Section links to external documents do not appear to be marked up as such (and
>> use a trailing dot in the section number which they should not)
> I am acutally not sure how to fix this. I removed the trailing dot
> (thanks for the hint) but when converting markdown to XML the section is
> not automatically recognized.
> My markdown looks like this:
> The authorization response as specified in Section 4.1.2 of [@!RFC6749]
>
> The XML file like this:
> The authorization response as specified in Section 4.1.2 of <xref
> target="RFC6749"></xref>
>
> Is there some example how to link the sections in external RFCs or
> should we create the links manually?

In XML yes, and kramdown will generate those for you. Dunno about mmark.

> ...

Best regards, Julian

_______________________________________________
art mailing list
art@ietf.org
https://www.ietf.org/mailman/listinfo/art