draft-deshpande-secevent-http-multi-set-push-00 early Httpdir review
Darrel Miller via Datatracker <noreply@ietf.org> Sun, 23 November 2025 22:18 UTC
Received: by mail2.ietf.org (Postfix) id B21FC8F2A250; Sun, 23 Nov 2025 14:18:20 -0800 (PST)
Delivered-To: ietfarch-httpbisa-archive-bis2juki@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B0C8F8F2A24F for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Sun, 23 Nov 2025 14:18:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -5.284
X-Spam-Level:
X-Spam-Status: No, score=-5.284 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.017, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org header.b="QAIDtZxO"; dkim=pass (2048-bit key) header.d=w3.org header.b="Q2BlPqHP"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U4YBg15szguE for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Sun, 23 Nov 2025 14:18:20 -0800 (PST)
Received: from mab.w3.org (mab.w3.org [IPv6:2600:1f18:7d7a:2700:d091:4b25:8566:8113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 662988F2A24A for <httpbisa-archive-bis2Juki@ietf.org>; Sun, 23 Nov 2025 14:18:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:Date:Reply-To:Message-ID:Cc:To:From:Content-Type:MIME-Version :In-Reply-To:References; bh=IFxdI6ViwCulDt7FLXpJwYsfalbReNSklTrIRmuIyU8=; b=Q AIDtZxOGtGCcpGsP23VOK0r0iNfpPvVyY45/k13UcGY1gwQbsm+TI+lEydNZNIiJAphgCUg3i8uru vXHCupwFu299SFAz0KZwOz/qZFQaMwAic/SDNa3FhckYC3yp732xpRY26wv94sVhipdZP57X5rb6K ovheQcXBcwVhjE9vh1KtoF4tJkDmaGe9KNhOAZVujt73Q4wBndaPYbGPSqlL1gKWn9CYQEtX1tuhQ IoGKFOWX9YtBt62CCxzT2Gf8dWj7SDLMgUDvendbmZk7hqFOxePrc+1Y3cqi8krPDmymharXWKm/W FBIcMyNo9Er1qu9XJ5ln77GNJbnDXMxAg==;
Received: from lists by mab.w3.org with local (Exim 4.96) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1vNIOD-00D1xc-1M for ietf-http-wg-dist@listhub.w3.org; Sun, 23 Nov 2025 22:17:01 +0000
Resent-Date: Sun, 23 Nov 2025 22:17:01 +0000
Resent-Message-Id: <E1vNIOD-00D1xc-1M@mab.w3.org>
Received: from ip-10-0-0-224.ec2.internal ([10.0.0.224] helo=puck.w3.org) by mab.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <noreply@ietf.org>) id 1vNIO8-00D1wZ-2q for ietf-http-wg@listhub.w3.internal; Sun, 23 Nov 2025 22:16:56 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Date:Reply-To:Message-ID:Subject:Cc:To:From:Content-Type:MIME-Version :In-Reply-To:References; bh=IFxdI6ViwCulDt7FLXpJwYsfalbReNSklTrIRmuIyU8=; t=1763936216; x=1764800216; b=Q2BlPqHPmyDjDt4t/IzyDsL/PBasUoBKYvBLBi9/WGQS++j lNRWYlRkfeEe/haexWJE+EOAQcJUjGSrE/xuvfhu4P7b2EUzYtSujmgX3voRJU7zZOzivWHwVULrn HiWNvnXGhpkRM7514FlYL8eOJ80DO2B8r+ENXBbUv+356S6oCN+xNt5uHKIuzyQWEZXj75cSkdbRh YLE8IIbpCGTZzE+ga8pI0lX6bzpjLSqQXXtnKZAYjtBExclTZyo0KWTLlDiaszxI9kQMOr9QKTBCO RK69PAH0XMGzvBOvmj1eO+X3sXR8SqiwoA+unTZ8hVCjjmmhjVc60OGl+ZMg7O+g==;
Received-SPF: pass (puck.w3.org: domain of ietf.org designates 166.84.6.31 as permitted sender) client-ip=166.84.6.31; envelope-from=noreply@ietf.org; helo=mail2.ietf.org;
Received: from mail2.ietf.org ([166.84.6.31]) by puck.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <noreply@ietf.org>) id 1vNIO8-001KfG-19 for ietf-http-wg@w3.org; Sun, 23 Nov 2025 22:16:56 +0000
Received: from [10.244.8.105] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 27A818F2A16C; Sun, 23 Nov 2025 14:16:53 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Darrel Miller via Datatracker <noreply@ietf.org>
To: ietf-http-wg@w3.org
Cc: draft-deshpande-secevent-http-multi-set-push.all@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.54.0
Auto-Submitted: auto-generated
Message-ID: <176393621302.2144597.492962217291019900@dt-datatracker-5bd94c585b-wk4l4>
Reply-To: Darrel Miller <darrel@tavis.ca>
Date: Sun, 23 Nov 2025 14:16:53 -0800
X-W3C-Hub-Spam-Status: No, score=-4.9
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DMARC_PASS=-0.001, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: puck.w3.org 1vNIO8-001KfG-19 072696ef39a502ce6d9c3ee18650348c
X-Original-To: ietf-http-wg@w3.org
Subject: draft-deshpande-secevent-http-multi-set-push-00 early Httpdir review
Archived-At: <https://www.w3.org/mid/176393621302.2144597.492962217291019900@dt-datatracker-5bd94c585b-wk4l4>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/53568
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
Document: draft-deshpande-secevent-http-multi-set-push Title: Push-Based Delivery For Multiple Security Event Token (SET) Using HTTP Reviewer: Darrel Miller Review result: On the Right Track I am the assigned HTTPDIR reviewer for this draft. Please treat these comments just like any other last call comments. Summary: On the right track Section 3.1 "A Transmitter MUST ensure that it includes the jti value of each SET it receives… to the Transmitter" I believe this should say "A Receiver MUST ensure" as it is referring to acknowledging the receipt of SETs back to the Transmitter. ## Section 3.3 Considering RFC8417 went to the effort of registering application/secevent+jwt it would seem unfortunate that this draft would fall back on using application/json. Would the authors consider registering application/secevents+json as a media type for containing a list of SETs? ## Section 3.4 "The Transmitter SHOULD limit 20 SETs in the sets." This sentence is a little difficult to parse considering the terminology. Perhaps wording such as, "The Transmitter SHOULD limit the sets object to 20 members" may reduce the confusion. References to RFC 7231 should be replaced by RFC 9110. ## Section 3.4.1 Success Response "If the Receiver is successful in processing the request, it MUST return the HTTP status code 202 (Accepted)." If the Receiver is only "accepting" the request then the 202 status code is fine. The term "processing the request" would suggest that a 200 response would be more appropriate. However, this statement in section 3 suggests that a 202 is more appropriate, "The SET Recipient SHALL NOT use the event acknowledgement mechanism to report event errors other than those relating to the parsing and validation of the SET." I would suggest replacing the word "processing" with "accepting". ## Section 3.4.2 Failure Response Considering this section specifically calls out that the Failure Response are not specific to SET specific errors, it would seem appropriate to use the http-problem media type RFC 9457: Problem Details for HTTP APIs for returning these errors rather than reusing the "err" and "description" structure used in the success response. ## Section 3.4.3 Error Response I am confused by this section. Section 3 suggests that only "parsing and validation" errors should be returned in the 202 response and section 3.4.2 describes the scenario there the HTTP request fails for generic reasons. I don't understand under which conditions a RFC 8935 style error response would be returned. Is this describing an HTTP response or simply qualifying the error code to be used in the setErrs list? Regards, Darrel
- draft-deshpande-secevent-http-multi-set-push-00 e… Darrel Miller via Datatracker