Httpdir early review of draft-ietf-wish-whep-00

Julian Reschke via Datatracker <noreply@ietf.org> Tue, 30 January 2024 14:23 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 019E1C151531 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 30 Jan 2024 06:23:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.756
X-Spam-Level:
X-Spam-Status: No, score=-2.756 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KqCiaVgu6POW for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 30 Jan 2024 06:22:56 -0800 (PST)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B14DBC1519A4 for <httpbisa-archive-bis2Juki@ietf.org>; Tue, 30 Jan 2024 06:22:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:Date:Reply-To:Message-ID:Cc:To:From:Content-Type:MIME-Version :In-Reply-To:References; bh=pkVh1bx47mJbw5vkO8f1YLdw7H0Cot/WpQX4ZrRsur4=; b=j NP5UriyvzpdKA8IuHQYOQcQ7YpICvSTY+Vu/IsjZwB/DgMRjZTsQCJWR4EKkQzyW3N740KcnslVjM nJHXIizZa1/TBebluivYlwmrtI9pGAfOIS/JITX2Ihwmpx5A69Et6nhVXgXVSrFFeJjb6k/JSe/v7 zp8fczJRDHtSB/WPkyEErjAzypTCcze5ouWbsxKz6xSU5PujtfLsNxRFKhlXzFaCLC2yndsIR9Xri 5z7zuVFRbzDQIobrnNFsDAvrY56qVvEK2ilU25WL+Ei6fGwV2yfzTLWqDBwrce1yEWuFZUBJl0ixb +e67m0h620eXfsdsWWq2GcEkZ4iYISIQg==;
Received: from lists by lyra.w3.org with local (Exim 4.94.2) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1rUozC-003Ars-KX for ietf-http-wg-dist@listhub.w3.org; Tue, 30 Jan 2024 14:21:14 +0000
Resent-Date: Tue, 30 Jan 2024 14:21:14 +0000
Resent-Message-Id: <E1rUozC-003Ars-KX@lyra.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by lyra.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <noreply@ietf.org>) id 1rUozA-003Aqr-T7 for ietf-http-wg@listhub.w3.org; Tue, 30 Jan 2024 14:21:12 +0000
Received: from mail.ietf.org ([50.223.129.194]) by mimas.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <noreply@ietf.org>) id 1rUoz8-006hYn-Nt for ietf-http-wg@w3.org; Tue, 30 Jan 2024 14:21:12 +0000
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D02B7C15152C; Tue, 30 Jan 2024 06:21:06 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Julian Reschke via Datatracker <noreply@ietf.org>
To: ietf-http-wg@w3.org
Cc: draft-ietf-wish-whep.all@ietf.org, wish@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.4.0
Auto-Submitted: auto-generated
Message-ID: <170662446683.21441.619227132747609754@ietfa.amsl.com>
Reply-To: Julian Reschke <julian.reschke@greenbytes.de>
Date: Tue, 30 Jan 2024 06:21:06 -0800
Received-SPF: pass client-ip=50.223.129.194; envelope-from=noreply@ietf.org; helo=mail.ietf.org
X-W3C-Hub-Spam-Status: No, score=-6.2
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1rUoz8-006hYn-Nt eb33272b7173ea39cb6fa551b75a00ea
X-Original-To: ietf-http-wg@w3.org
Subject: Httpdir early review of draft-ietf-wish-whep-00
Archived-At: <https://www.w3.org/mid/170662446683.21441.619227132747609754@ietfa.amsl.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/51753
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Reviewer: Julian Reschke
Review result: Not Ready

I have done a quick review focusing only on HTTP related parts, and on general
RFC style.

Style nits:

- please separate artwork for request / responses and tag them with
"httpmessage" - one use of "COULD" (that's not a BCP 14 keyword) - please use
"Section x of [REF]" instead of "[REF] section x" - most artwork is too wide
for plain text rendering - there's no reason to specify an abbreivated title
when the title of the document is already short enough - 6.2.1 has prose in
artwork instead of plain text, thus the warning about RFC 8141 being unused

HTTP remarks:

- "The WHEP Endpoints MUST return an "405 Method Not Allowed" response for any
HTTP GET, HEAD or PUT requests on the endpoint URL in order to reserve its
usage for future versions of this protocol specification." - I think this is
highly problematic. If you want to reserve specific uses for GET, defining
media types for that purpose and doing content negotiation makes more sense

- there is a trend towards being incorrect or too specific with status codes;
for instance, 409 sounds incorrect if the it's really about the endpoint not
being ready; in which case a 5xx makes more sense. Furthermore, requiring 204
is too specific; there's really no reason why an empty 200 reponse shouldn't
work as well. It's also not clear why "307" "MUST" be supported, and 308 is not
mentioned at all.

- don't be too specific with additional requirements on requests/responses, in
particular when they are already defined by HTTP (see, for instance, handling
of ETags and conditional header fields)

In general, I recommend reading https://www.rfc-editor.org/rfc/rfc9205.html and
to revise the document where it either is to specific, or tries to redefine
that HTTP already specifies.