[httpapi] Murray Kucherawy's No Objection on draft-ietf-httpapi-link-template-03: (with COMMENT)

Murray Kucherawy via Datatracker <noreply@ietf.org> Thu, 15 February 2024 15:19 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: httpapi@ietf.org
Delivered-To: httpapi@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 842FDC17C8BA; Thu, 15 Feb 2024 07:19:26 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Murray Kucherawy via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-httpapi-link-template@ietf.org, httpapi-chairs@ietf.org, httpapi@ietf.org, rsalz@akamai.com, darrel@tavis.ca
X-Test-IDTracker: no
X-IETF-IDTracker: 12.5.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Murray Kucherawy <superuser@gmail.com>
Message-ID: <170801036653.46821.17630276085491321811@ietfa.amsl.com>
Date: Thu, 15 Feb 2024 07:19:26 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/httpapi/yzc1vpuU2Cl3VPPrUYCpyAJb5L4>
Subject: [httpapi] Murray Kucherawy's No Objection on draft-ietf-httpapi-link-template-03: (with COMMENT)
X-BeenThere: httpapi@ietf.org
X-Mailman-Version: 2.1.39
List-Id: Building Blocks for HTTP APIs <httpapi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/httpapi>, <mailto:httpapi-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/httpapi/>
List-Post: <mailto:httpapi@ietf.org>
List-Help: <mailto:httpapi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/httpapi>, <mailto:httpapi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Feb 2024 15:19:26 -0000

Murray Kucherawy has entered the following ballot position for
draft-ietf-httpapi-link-template-03: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-httpapi-link-template/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Feedback from incoming ART AD, Orie Steele:

I'd prefer to see specific security considerations associated with "Display
Strings", based on this MUST:

"These Parameter values MUST be Strings, unless they contain non-ASCII
characters, in which case they MUST be Display Strings. "

... and the following comment in the normative reference:

"It is NOT RECOMMENDED that they be used in situations where a String (Section
3.3.3) or Token (Section 3.3.4) would be adequate, because Unicode has
processing considerations (e.g., normalization) and security considerations
(e.g., homograph attacks) that make it more difficult to handle correctly."