Re: [httpapi] Idempotency Key - Are we ready for last call?

Mark Nottingham <mnot@mnot.net> Tue, 09 January 2024 04:05 UTC

Return-Path: <mnot@mnot.net>
X-Original-To: httpapi@ietfa.amsl.com
Delivered-To: httpapi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23CA7C1CAF40 for <httpapi@ietfa.amsl.com>; Mon, 8 Jan 2024 20:05:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.805
X-Spam-Level:
X-Spam-Status: No, score=-2.805 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mnot.net header.b="VVljPe/C"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="E/+VAdav"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JVT5qKC9XK5q for <httpapi@ietfa.amsl.com>; Mon, 8 Jan 2024 20:05:07 -0800 (PST)
Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CE58BC1CAF3E for <httpapi@ietf.org>; Mon, 8 Jan 2024 20:05:07 -0800 (PST)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 7A38D5C033B; Mon, 8 Jan 2024 23:05:06 -0500 (EST)
Received: from mailfrontend1 ([10.202.2.162]) by compute4.internal (MEProxy); Mon, 08 Jan 2024 23:05:06 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm3; t=1704773106; x=1704859506; bh=EYaZWPhEdJ8uhAaxHHgtNznbQCJbWrMIWCCcm6rpswk=; b= VVljPe/CkXo7ZvpjJS5U67AWbd5uwN1td/BiJ5K6QW8mJoDtK/m4G91BL6Jatp4L GMZMCqz5XeuF/K13/7IjVEaTDZ137liN1Oyldh7LjCiV36chhOWLkRO8fF1e9kG5 ZzaMPqhaPo73U5QXSWATtd9UeT3DJGlZikPCJkf/eYd8EQIARYlmQJsbeTEnZxDC gYY6+vOVeM+2kk9lz+I1Jkvd9oyPurELZG4YmCah47tRjo0KHBdU74mWO52im+6J Ms8fZMQW5bL6ohgVuCx1yVnkd3D+lw9gnFquNzRbNDXORdoHULQP5JpOA0+Ce1FK Auj2Qaf3uj6AcP/rAOk4FA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1704773106; x= 1704859506; bh=EYaZWPhEdJ8uhAaxHHgtNznbQCJbWrMIWCCcm6rpswk=; b=E /+VAdav5Jwrj+BDCVUovB1KSudrIraRCwDjfPSkhJMnTBLD7pFtw45TpI6v4VVm8 NFWVphjPIe1qnGbpoge31y8brne6cULP1r02bc0KJ5cSlD2WRs5un7xMpxIAFRdo NBH+iaqAiFByYXpUvjyrrkwq13dx3LWq6qVNuA3OO7hz+WoFoGFlB/9SOiFHej4X fJCRC8LJVDpNh4NsmmeMHS7+QtdneQYsjsnkoXXWNfS7Qav6zzCHSDO1udVT1Sbh UdErOzUBKUzZdZSKfiYzOpdz6AmC/I1fqVdQuG/ikQYHYx/WFyVZo3uvf1wDjmSr 3YWLulyTLypxt0EChgQBw==
X-ME-Sender: <xms:8sWcZdEugefb_hmpGVqBOhmxD3zsaEBKxWyAAubNrwgqFIVjCBtQ5w> <xme:8sWcZSXRslADo7V4fK5NQpCAAMf7vDPzl3wVwqp1Wpq8ljtIz2q6_8QkzNbRpgNDH tc28b3yqRkXfdO6sA>
X-ME-Received: <xmr:8sWcZfKiht_jQUpk1Ry-8Eqy-rUf2XcBdfGQTy5R8JpXg_GbxP0zj9NKZj3r6Rvpd7A0B23M9ysONn_mqbNAZ4ThKXaUjJvi8RdCh4MowZf--gd7sNUuqR96>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvkedrvdehkedgieejucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurheptggguffhjgffvefgkfhfvffosehtqhhmtdhhtdejnecuhfhrohhmpeforghr khcupfhothhtihhnghhhrghmuceomhhnohhtsehmnhhothdrnhgvtheqnecuggftrfgrth htvghrnhepieetffefudevffevheehtefftedtteffgeejffduhfegheeliedvhfejgeeh heetnecuffhomhgrihhnpehivghtfhdrohhrghdpmhhnohhtrdhnvghtnecuvehluhhsth gvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepmhhnohhtsehmnhhothdr nhgvth
X-ME-Proxy: <xmx:8sWcZTE5tHq7WaXJFz_L6-fShYLANmnehZ8pCAQUWLv2gXFBYXzYOg> <xmx:8sWcZTUkjp1PM33oaVc8kMBOnmcrnYlgzpxZPZSrLtF-m27eCS5jpw> <xmx:8sWcZeOkz6F9J5J5jWNNrtuSaYGPw_S3T6FPhyt4PPpqB1cc_zksTQ> <xmx:8sWcZQijQ3tHFkHd-Af5wAu5LXh7OxdpEnIuusRjWa8s4bvltUfkBA>
Feedback-ID: ie6694242:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 8 Jan 2024 23:05:04 -0500 (EST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.300.61.1.2\))
From: Mark Nottingham <mnot@mnot.net>
In-Reply-To: <SJ2PR01MB8102C62EF6B7C7755D136577A3652@SJ2PR01MB8102.prod.exchangelabs.com>
Date: Tue, 09 Jan 2024 15:05:01 +1100
Cc: "httpapi@ietf.org" <httpapi@ietf.org>, Sanjay Dalal <sanjay.dalal@gmail.com>, "jayadebaj@gmail.com" <jayadebaj@gmail.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <7082EA08-5332-4A50-A9A9-D1F6325E71C3@mnot.net>
References: <SJ2PR01MB8102C62EF6B7C7755D136577A3652@SJ2PR01MB8102.prod.exchangelabs.com>
To: Darrel Miller <darrel@tavis.ca>
X-Mailer: Apple Mail (2.3774.300.61.1.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/httpapi/sEHtA-QOM9a4NPN1OUzf1K4S8Qc>
Subject: Re: [httpapi] Idempotency Key - Are we ready for last call?
X-BeenThere: httpapi@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Building Blocks for HTTP APIs <httpapi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/httpapi>, <mailto:httpapi-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/httpapi/>
List-Post: <mailto:httpapi@ietf.org>
List-Help: <mailto:httpapi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/httpapi>, <mailto:httpapi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jan 2024 04:05:12 -0000

I think this document needs significant work before it's ready to publish.

I've made a number of editorial suggestions in a PR.

More substantially, there are many vague and open statements in this specification. For example:

> Uniqueness of the key MUST be defined by the resource owner and MUST be implemented by the clients of the resource server.

How is this interoperable? If the resource has to document the syntax and semantics of the value, what does standardising it add?

> The resource MAY enforce time based idempotency keys, thus, be able to purge or delete a key upon its expiry. The resource server SHOULD define such expiration policy and publish it in the documentation.

Again, this seems counter to the goal of interoperability. If there's an expiration mechanism, a client should be able to discover it in an interoperable fashion.

It may be that a future development -- e.g., something in OpenAPI -- might provide these mechanisms. If that's the case, fine, but this specification doesn't need to invite interop problems by making these statements; it should be silent.

Throughout, RFC2119 requirements are misused. Concentrate on what MUST be done for interoperability, and remove the MAYs and SHOULDs.

Does the 'idempotency fingerprint' concept really add anything here? I understand that some implementations may do it, but should we document it as part of the standard?

Section 2.7 defines multiple ways to signal errors -- again, bad for interoperability. Choose one, unless there is a convincing reason why more than one method is necessary (in which case, document when it's appropriate to use each). 

Those are the high-level concerns I had from a quick pass over the document.

Cheers,




> On 6 Jan 2024, at 12:39 pm, Darrel Miller <darrel@tavis.ca> wrote:
> 
> Hey Sanjay, Jeyadeba,
> 
> Other than Mark's question about Repeatable Read, there are no more open issues for this document.  Are you ok for me to issue last call on this document? 
> I'll be doing the shepherd write up for it.
> 
> Darrel
> -- 
> httpapi mailing list
> httpapi@ietf.org
> https://www.ietf.org/mailman/listinfo/httpapi


--
Mark Nottingham   https://www.mnot.net/