Re: [httpapi] Link relationship types for authentication
Graham Cox <graham@grahamcox.co.uk> Tue, 26 January 2021 21:24 UTC
Return-Path: <graham@grahamcox.co.uk>
X-Original-To: httpapi@ietfa.amsl.com
Delivered-To: httpapi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E6883A0F06 for <httpapi@ietfa.amsl.com>; Tue, 26 Jan 2021 13:24:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.004
X-Spam-Level:
X-Spam-Status: No, score=0.004 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=grahamcox-co-uk.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 33ofy9b80OL3 for <httpapi@ietfa.amsl.com>; Tue, 26 Jan 2021 13:24:43 -0800 (PST)
Received: from mail-io1-xd29.google.com (mail-io1-xd29.google.com [IPv6:2607:f8b0:4864:20::d29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D5B533A0FED for <httpapi@ietf.org>; Tue, 26 Jan 2021 13:24:40 -0800 (PST)
Received: by mail-io1-xd29.google.com with SMTP id p72so36666936iod.12 for <httpapi@ietf.org>; Tue, 26 Jan 2021 13:24:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=grahamcox-co-uk.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=cpmOL7YEtIfE0P3uaDyK+guB+lGyAqgCyt/CInP/fgk=; b=tNAsyS4wewhVG4fw+bzseBt8kd8vQopW5+kQFd4u+IZzg5YU+RhwkwI/xgSFoM/RI/ onnN7SavRoKRATU+lxbCVhe1jQWBSa6V++y+UYirNfs/NmTbP1Q6IpEddB5cCr1bGMj6 kptYCF0YV5qxqj3JtAcQxLNjZf4cKunqfhImY9XYVBiLE/rO88IzkD8SOc29lM5fFgKq 1eq2PrV5tbRwHf+wqfhiFMOdaDVPdOCbTRb/AGq+z6j48CaLaOMzI4zwVB+xriXIWvQl jRmBF7s8OgGdCDIvYinis7Ysvfsau87S4caLrkzwMYks0bBikZLwGlDo2JntMuMrK0VO lYiQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=cpmOL7YEtIfE0P3uaDyK+guB+lGyAqgCyt/CInP/fgk=; b=VzKz10jGpGgLIL6TgvpP0+zQA4efwHMDEelxLb11ED215tRMRfd7koXhXWG8YtMY7G U3DHV84q0qK/WqXk6JCD7Kj4W+iB8ZcIlpML9NRhEniCVrt7CVNe5abZltBv5PRWzi/u ZETQdx8GNP2PFQuBg7ws+1DODXHgPm7LGqpFInvMac47ZaWbKE8aZM11UqjBeC78fuxt jmmSe3xkgryd6P7OONmlk6Umdbf3EANNT4d5mQIgqLM5WupohtoyLMwGsslTdrlQqQ1z N2pPTzEuGo3h5Ccci6qGEL/xB1NlENhHNJfl77RBOPNvxjwO5JtGdFajPxCqt8CSxbvy MVfQ==
X-Gm-Message-State: AOAM532oPOfcrEv9qydaq+WdK2ivl9agcCtbdeHVLHQZo4LEqDFz1eCN t9LefHl77jPfOqOZuFZV9JtUUV2Z/FmeqfPA8ISn+aBX8l25/w==
X-Google-Smtp-Source: ABdhPJz+pC4v2JpFOqJqQujagKXSS5zVOrlli+5ck8Y09cCGBgcqfVrmkJOjLEJNZjLu2ZHsRp3KNXIKw0AML4dQqbU=
X-Received: by 2002:a05:6e02:1787:: with SMTP id y7mr5997970ilu.233.1611696279711; Tue, 26 Jan 2021 13:24:39 -0800 (PST)
MIME-Version: 1.0
References: <CAO0N9X4TTcQTk_Nrd9hYCs3wFkx6pNfsXaig7BVFzvVFQU-1+Q@mail.gmail.com> <DM6PR00MB08458672E57AACC3BB8367EEF0BC9@DM6PR00MB0845.namprd00.prod.outlook.com> <CAP9qbHXLep=+5dBxqSh829PSkKVjxcEnRn6XHWcRdgQrHc9uAA@mail.gmail.com> <e0db5e86-0b68-7b9a-b9c5-ea12745aab93@evertpot.com>
In-Reply-To: <e0db5e86-0b68-7b9a-b9c5-ea12745aab93@evertpot.com>
From: Graham Cox <graham@grahamcox.co.uk>
Date: Tue, 26 Jan 2021 21:24:26 +0000
Message-ID: <CAPBurBvUuQZigMCPHu3h5FhyNJDJauzZQdWbNR2R5yxWO9R_4w@mail.gmail.com>
To: httpapi@ietf.org
Content-Type: multipart/alternative; boundary="0000000000003d102905b9d448c4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/httpapi/bCZPem4Hre7WJlmZRtgRb4BwRK0>
Subject: Re: [httpapi] Link relationship types for authentication
X-BeenThere: httpapi@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Building Blocks for HTTP APIs <httpapi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/httpapi>, <mailto:httpapi-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/httpapi/>
List-Post: <mailto:httpapi@ietf.org>
List-Help: <mailto:httpapi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/httpapi>, <mailto:httpapi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Jan 2021 21:24:48 -0000
Apologies if this has already been covered, but have you looked into the overlap between this and OpenID Connect? I'm far from an expert, but it seems that some - though not all - of the relations defined here correspond well with the actions that OIDC offer, though obviously they work in notably different ways. (The *authenticated-as* relation doesn't have any direct mapping in OIDC that I can think of, but they others all map on to *something*) Cheers -- Graham Cox On Tue, 26 Jan 2021 at 21:05, Evert Pot <me@evertpot.com> wrote: > On 2021-01-26 10:04 a.m., Roberto Polli wrote: > > Hi, > > > > > > Il giorno mar 26 gen 2021 alle ore 03:52 Darrel Miller > > <Darrel.Miller=40microsoft.com@dmarc.ietf.org> ha scritto: > >> Do you know if Evert posted this to the Link Relations Type mailing > list? > >> https://mailarchive.ietf.org/arch/browse/link-relations/ > > Maybe the OAuth workgroup could be interested or working on something > > like this, too. > > Pax, > > R. > > I've sent an email to their list a while back. There was some feedback, > but nothing really substantial: > > https://mailarchive.ietf.org/arch/msg/oauth/SqVD1YBqq-XCUREEVu9YXjKmrto/ > > So, I'm not sure if there's more to be done there(?). > > For what it's worth, in the years since I've published the first draft, > I've had more than a few people tell me they use (some of) these link > relationships in their system, usually after it was found with a google > search. > > I think oauth2 adoption would be great. One of it's failings I think is > the fact that user agents can't discover anymore how to authenticate a > user after getting a 401, so this is a nice step in the direction of > potentially solving that. > > Evert > > -- > httpapi mailing list > httpapi@ietf.org > https://www.ietf.org/mailman/listinfo/httpapi >
- [httpapi] Link relationship types for authenticat… Gabriel Sullice
- Re: [httpapi] Link relationship types for authent… Darrel Miller
- Re: [httpapi] Link relationship types for authent… Roberto Polli
- Re: [httpapi] Link relationship types for authent… Evert Pot
- Re: [httpapi] Link relationship types for authent… Evert Pot
- Re: [httpapi] Link relationship types for authent… Graham Cox
- Re: [httpapi] Link relationship types for authent… Evert Pot
- Re: [httpapi] Link relationship types for authent… Erik Wilde
- Re: [httpapi] Link relationship types for authent… Mark Nottingham
- Re: [httpapi] Link relationship types for authent… Darrel Miller