From ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org  Fri Feb 24 15:31:56 2023
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 4D803C14CE44
	for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 24 Feb 2023 15:31:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.048
X-Spam-Level:
X-Spam-Status: No, score=-5.048 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25,
	HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_MED=-2.3,
	RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001,
	SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001,
	URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
	header.d=zoho.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id YxdvvDN5zBMZ
	for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>;
	Fri, 24 Feb 2023 15:31:52 -0800 (PST)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id 4214EC14F744
	for <httpbisa-archive-bis2Juki@lists.ietf.org>; Fri, 24 Feb 2023 15:31:51 -0800 (PST)
Received: from lists by lyra.w3.org with local (Exim 4.94.2)
	(envelope-from <ietf-http-wg-request@listhub.w3.org>)
	id 1pVhXO-00BbLU-6b
	for ietf-http-wg-dist@listhub.w3.org; Fri, 24 Feb 2023 23:31:38 +0000
Resent-Date: Fri, 24 Feb 2023 23:31:38 +0000
Resent-Message-Id: <E1pVhXO-00BbLU-6b@lyra.w3.org>
Received: from mimas.w3.org ([128.30.52.79])
	by lyra.w3.org with esmtps  (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
	(Exim 4.94.2)
	(envelope-from <mellowmutt@zoho.com>)
	id 1pVhXM-00BbKX-FS
	for ietf-http-wg@listhub.w3.org; Fri, 24 Feb 2023 23:31:37 +0000
Received: from sender4-pp-o90.zoho.com ([136.143.188.90])
	by mimas.w3.org with esmtps  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
	(Exim 4.94.2)
	(envelope-from <mellowmutt@zoho.com>)
	id 1pVhXL-00D4XK-1y
	for ietf-http-wg@w3.org; Fri, 24 Feb 2023 23:31:36 +0000
ARC-Seal: i=1; a=rsa-sha256; t=1677281471; cv=none; 
	d=zohomail.com; s=zohoarc; 
	b=gJgSkQMxdf7N+spqz7/MgedWPEFhLTXfjKSaowtYjdTtJks3zpnbHylV4hU7sJsPsPix60nbSE1MxhDFmnCgB+ny4a8nxffIscqRhesPnEJchBQ4cdiRkfyzXwnJoG3vhQrDU+cxT4URY4y5vN7JtRAyHTKqbV5i+qAH14oCZRk=
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; 
	t=1677281471; h=Content-Type:Cc:Date:From:In-Reply-To:MIME-Version:Message-ID:References:Subject:To; 
	bh=wKofeRrDFwiRCxEJJmahzF1zQ5bk9AuacZwIat7mETY=; 
	b=ZVns9YBnOCwDFcMhJRLQ39+Xn0HrUm7v+ecqMq7GVI9gFzjbJ1k2sxMyPNV8/P+LXsZL2GOE8YBm0r8GXqgHzo5JfT7kl3kCNVUnlllN257Q8EsZg7B7OmREkmuYHhxtFQ9TCPbXu2JEXJpOx5shtSIhp2IERp/xXlkW53Yed9Q=
ARC-Authentication-Results: i=1; mx.zohomail.com;
	dkim=pass  header.i=zoho.com;
	spf=pass  smtp.mailfrom=mellowmutt@zoho.com;
	dmarc=pass header.from=<mellowmutt@zoho.com>
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1677281471;
	s=zm2022; d=zoho.com; i=mellowmutt@zoho.com;
	h=Date:Date:From:From:To:To:Cc:Cc:Message-Id:Message-Id:In-Reply-To:References:Subject:Subject:MIME-Version:Content-Type:Feedback-ID:Reply-To;
	bh=wKofeRrDFwiRCxEJJmahzF1zQ5bk9AuacZwIat7mETY=;
	b=LX4KUrXrka19nK5TK3UdpFBnuwM0swOz4TsV3ND1tMiSP+gG/RkDh/w14c+iYv+W
	1pSK9C5b4WrCoZCd0pDsT6uwNRtAwjlcPeovP5VMKKiVPPHsGBVuwiSGor9jx+jAeFP
	6DJt5OUFOlm64gSWtIhZfZ3fml5Akt60AU6c3yjo=
Received: from mail.zoho.com by mx.zohomail.com
	with SMTP id 1677281471326123.1736985530639; Fri, 24 Feb 2023 15:31:11 -0800 (PST)
Received: from  [65.117.211.248] by mail.zoho.com
	with HTTP;Fri, 24 Feb 2023 15:31:11 -0800 (PST)
Date: Fri, 24 Feb 2023 15:31:11 -0800
From: Eric J Bowman <mellowmutt@zoho.com>
To: "Christopher Wood" <caw@heapingbits.net>
Cc: "mark nottingham" <mnot@mnot.net>,
	"http working group" <ietf-http-wg@w3.org>,
	"tommy pauly" <tpauly@apple.com>
Message-Id: <18685c42b44.e1acca954877.5894602446250292773@zoho.com>
In-Reply-To: <466C7100-4FB1-407E-A488-5AE553460C4C@heapingbits.net>
References: <6532E43F-74FD-46B4-8D28-9DB03452A689@mnot.net> <466C7100-4FB1-407E-A488-5AE553460C4C@heapingbits.net>
MIME-Version: 1.0
Content-Type: multipart/alternative; 
	boundary="----=_Part_12720_1222574198.1677281471300"
Importance: Medium
User-Agent: Zoho Mail
X-Mailer: Zoho Mail
Feedback-ID: rr08011228aba8d8d28529e037f7deef26000010f63287ad30d0712c53be8dfd60fc8a3ac912155557c0f37a90:zu080112274271e8d95eef8ec989ab9f7f000078a866e9ee3a019eb914913dfd74ddd2776bfcb1b72bec2657:rf080112328a5d122a4f9148d17c527ae60000aaa6c8df6eaf126440938537f0ceeb1570a91df988161074d4afc5c5eddbcd336554a540:ZohoMail
Received-SPF: pass client-ip=136.143.188.90; envelope-from=mellowmutt@zoho.com; helo=sender4-pp-o90.zoho.com
X-W3C-Hub-DKIM-Status: validation passed: (address=mellowmutt@zoho.com domain=zoho.com), signature is good
X-W3C-Hub-DKIM-Status: validation passed: (address=mellowmutt@zoho.com domain=mellowmutt@zoho.com), signature is good
X-W3C-Hub-Spam-Status: No, score=-4.1
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1pVhXL-00D4XK-1y bba6a8d0cf32556683f7a5a2369fd0f3
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for Adoption: HTTP Unprompted Authentication
Archived-At: <https://www.w3.org/mid/18685c42b44.e1acca954877.5894602446250292773@zoho.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/50749
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

------=_Part_12720_1222574198.1677281471300
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit

No offense to Chris, but ugh. Cookies have value, but they're still fundamentally at odds with the architectural style derived from reality. The entire notion of unprompted authentication is a red flag to me, architecturally speaking, especially to support a niche use-case.



I don't see this as a "super cookie," but I can't put my finger on why it worries me along those lines, as an end-run around how HTTP Auth "should" work, at least in what's left of my brain. Mainstream or niche, to me, any use-case should conform to... well... my notion of "proper" architecture. See "Minority Report" lol, this is pre-crime...



-Eric







---- On Tue, 07 Feb 2023 12:41:02 -0800 Christopher Wood <caw@heapingbits.net> wrote ---



I'm supportive of adopting this draft on the basis of the desired use cases. They may be rather niche -- and should likely be added to the draft [0] -- but I understand them to have value. 
 
I do have some questions about the technical contents, which I've filed issues to track [1,2,3,4,5]. I'm happy to help seek resolution of those on GitHub. 
 
Are there any implementations of this mechanism yet? I would be happy to help provide an implementation of the server piece for interop tests. 
 
Best, 
Chris 
 
[0] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/22 
[1] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/17 
[2] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/18 
[3] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/19 
[4] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/20 
[5] https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/21 
 
> On Feb 7, 2023, at 12:58 AM, Mark Nottingham <mailto:mnot@mnot.net> wrote: 
> 
> Hello everyone, 
> 
> We first discussed this draft at IETF114[1],  saw implementation interest at IETF115, [2] and finally had some more list discussion. 
> 
> This is a Call for Adoption for: 
> https://www.ietf.org/archive/id/draft-schinazi-httpbis-unprompted-auth-01.html 
> 
> Please indicate (in response to this message) whether you support adoption, and whether you intend to implement. 
> 
> The CfA will last for two weeks. 
> 
> Cheers, 
> 
> 
> 1. https://httpwg.org/wg-materials/ietf114/minutes.html#transport-auth-david-schinazi 
> 1. https://httpwg.org/wg-materials/ietf115/minutes.html#unprompted-auth 
> 
> -- 
> Mark Nottingham https://www.mnot.net/ 
> 
>
------=_Part_12720_1222574198.1677281471300
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>=
<meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"></h=
ead><body ><div style=3D"font-family: Verdana, Arial, Helvetica, sans-serif=
; font-size: 10pt;"><div style=3D"color: rgb(0, 0, 0); font-family: Verdana=
, Arial, Helvetica, sans-serif; font-size: 13.3333px; font-style: normal; f=
ont-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;=
 letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; t=
ext-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -we=
bkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); text-dec=
oration-thickness: initial; text-decoration-style: initial; text-decoration=
-color: initial;">No offense to Chris, but ugh. Cookies have value, but the=
y're still fundamentally at odds with the architectural style derived from =
reality. The entire notion of unprompted authentication is a red flag to me=
, architecturally speaking, especially to support a niche use-case.<br></di=
v><div style=3D"color: rgb(0, 0, 0); font-family: Verdana, Arial, Helvetica=
, sans-serif; font-size: 13.3333px; font-style: normal; font-variant-ligatu=
res: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: n=
ormal; orphans: 2; text-align: start; text-indent: 0px; text-transform: non=
e; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-w=
idth: 0px; background-color: rgb(255, 255, 255); text-decoration-thickness:=
 initial; text-decoration-style: initial; text-decoration-color: initial;">=
<br></div><div style=3D"color: rgb(0, 0, 0); font-family: Verdana, Arial, H=
elvetica, sans-serif; font-size: 13.3333px; font-style: normal; font-varian=
t-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-sp=
acing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transf=
orm: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-=
stroke-width: 0px; background-color: rgb(255, 255, 255); text-decoration-th=
ickness: initial; text-decoration-style: initial; text-decoration-color: in=
itial;">I don't see this as a "super cookie," but I can't put my finger on =
why it worries me along those lines, as an end-run around how HTTP Auth "sh=
ould" work, at least in what's left of my brain. Mainstream or niche, to me=
, any use-case should conform to... well... my notion of "proper" architect=
ure. See "Minority Report" lol, this is pre-crime...<br></div><div style=3D=
"color: rgb(0, 0, 0); font-family: Verdana, Arial, Helvetica, sans-serif; f=
ont-size: 13.3333px; font-style: normal; font-variant-ligatures: normal; fo=
nt-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans:=
 2; text-align: start; text-indent: 0px; text-transform: none; white-space:=
 normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; back=
ground-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-=
decoration-style: initial; text-decoration-color: initial;"><br></div><div =
style=3D"color: rgb(0, 0, 0); font-family: Verdana, Arial, Helvetica, sans-=
serif; font-size: 13.3333px; font-style: normal; font-variant-ligatures: no=
rmal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
orphans: 2; text-align: start; text-indent: 0px; text-transform: none; whit=
e-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0=
px; background-color: rgb(255, 255, 255); text-decoration-thickness: initia=
l; text-decoration-style: initial; text-decoration-color: initial;">-Eric<b=
r></div><div style=3D"color: rgb(0, 0, 0); font-family: Verdana, Arial, Hel=
vetica, sans-serif; font-size: 13.3333px; font-style: normal; font-variant-=
ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spac=
ing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transfor=
m: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-st=
roke-width: 0px; background-color: rgb(255, 255, 255); text-decoration-thic=
kness: initial; text-decoration-style: initial; text-decoration-color: init=
ial;"><br></div><div class=3D"zmail_extra_hr" style=3D"border-top: 1px soli=
d rgb(204, 204, 204); height: 0px; margin-top: 10px; margin-bottom: 10px; l=
ine-height: 0px;"><br></div><div class=3D"zmail_extra" data-zbluepencil-ign=
ore=3D"true"><div><br></div><div id=3D"Zm-_Id_-Sgn1">---- On Tue, 07 Feb 20=
23 12:41:02 -0800 <b>Christopher Wood &lt;caw@heapingbits.net&gt;</b> wrote=
 ---<br></div><div><br></div><blockquote id=3D"blockquote_zmail" style=3D"m=
argin: 0px;"><div>I'm supportive of adopting this draft on the basis of the=
 desired use cases. They may be rather niche -- and should likely be added =
to the draft [0] -- but I understand them to have value. <br> <br>I do have=
 some questions about the technical contents, which I've filed issues to tr=
ack [1,2,3,4,5]. I'm happy to help seek resolution of those on GitHub. <br>=
 <br>Are there any implementations of this mechanism yet? I would be happy =
to help provide an implementation of the server piece for interop tests. <b=
r> <br>Best, <br>Chris <br> <br>[0] <a href=3D"https://github.com/DavidSchi=
nazi/draft-schinazi-httpbis-transport-auth/issues/22" target=3D"_blank">htt=
ps://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/=
22</a> <br>[1] <a href=3D"https://github.com/DavidSchinazi/draft-schinazi-h=
ttpbis-transport-auth/issues/17" target=3D"_blank">https://github.com/David=
Schinazi/draft-schinazi-httpbis-transport-auth/issues/17</a> <br>[2] <a hre=
f=3D"https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth=
/issues/18" target=3D"_blank">https://github.com/DavidSchinazi/draft-schina=
zi-httpbis-transport-auth/issues/18</a> <br>[3] <a href=3D"https://github.c=
om/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/19" target=3D=
"_blank">https://github.com/DavidSchinazi/draft-schinazi-httpbis-transport-=
auth/issues/19</a> <br>[4] <a href=3D"https://github.com/DavidSchinazi/draf=
t-schinazi-httpbis-transport-auth/issues/20" target=3D"_blank">https://gith=
ub.com/DavidSchinazi/draft-schinazi-httpbis-transport-auth/issues/20</a> <b=
r>[5] <a href=3D"https://github.com/DavidSchinazi/draft-schinazi-httpbis-tr=
ansport-auth/issues/21" target=3D"_blank">https://github.com/DavidSchinazi/=
draft-schinazi-httpbis-transport-auth/issues/21</a> <br> <br>&gt; On Feb 7,=
 2023, at 12:58 AM, Mark Nottingham &lt;<a href=3D"mailto:mnot@mnot.net" ta=
rget=3D"_blank">mnot@mnot.net</a>&gt; wrote: <br>&gt; <br>&gt; Hello everyo=
ne, <br>&gt; <br>&gt; We first discussed this draft at IETF114[1],  saw imp=
lementation interest at IETF115, [2] and finally had some more list discuss=
ion. <br>&gt; <br>&gt; This is a Call for Adoption for: <br>&gt; <a href=3D=
"https://www.ietf.org/archive/id/draft-schinazi-httpbis-unprompted-auth-01.=
html" target=3D"_blank">https://www.ietf.org/archive/id/draft-schinazi-http=
bis-unprompted-auth-01.html</a> <br>&gt; <br>&gt; Please indicate (in respo=
nse to this message) whether you support adoption, and whether you intend t=
o implement. <br>&gt; <br>&gt; The CfA will last for two weeks. <br>&gt; <b=
r>&gt; Cheers, <br>&gt; <br>&gt; <br>&gt; 1. <a href=3D"https://httpwg.org/=
wg-materials/ietf114/minutes.html#transport-auth-david-schinazi" target=3D"=
_blank">https://httpwg.org/wg-materials/ietf114/minutes.html#transport-auth=
-david-schinazi</a> <br>&gt; 1. <a href=3D"https://httpwg.org/wg-materials/=
ietf115/minutes.html#unprompted-auth" target=3D"_blank">https://httpwg.org/=
wg-materials/ietf115/minutes.html#unprompted-auth</a> <br>&gt; <br>&gt; -- =
<br>&gt; Mark Nottingham <a href=3D"https://www.mnot.net/" target=3D"_blank=
">https://www.mnot.net/</a> <br>&gt; <br>&gt; <br> <br> <br></div></blockqu=
ote></div><div><br></div></div><br></body></html>
------=_Part_12720_1222574198.1677281471300--


