Re: Call for adoption: draft-reschke-httpauth-auth-info-00

Julian Reschke <julian.reschke@greenbytes.de> Thu, 29 January 2015 07:43 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E32851A9007 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 28 Jan 2015 23:43:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LniDWWdYsv9l for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 28 Jan 2015 23:43:51 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38AE61A8F51 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Wed, 28 Jan 2015 23:43:51 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YGjjZ-0007pS-OM for ietf-http-wg-dist@listhub.w3.org; Thu, 29 Jan 2015 07:41:49 +0000
Resent-Date: Thu, 29 Jan 2015 07:41:49 +0000
Resent-Message-Id: <E1YGjjZ-0007pS-OM@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <julian.reschke@greenbytes.de>) id 1YGjjU-0007oG-1F for ietf-http-wg@listhub.w3.org; Thu, 29 Jan 2015 07:41:44 +0000
Received: from mail.greenbytes.de ([217.91.35.233]) by lisa.w3.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.72) (envelope-from <julian.reschke@greenbytes.de>) id 1YGjjS-0003R4-U1 for ietf-http-wg@w3.org; Thu, 29 Jan 2015 07:41:43 +0000
Received: from [192.168.2.175] (unknown [93.217.85.143]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client did not present a certificate) by mail.greenbytes.de (Postfix) with ESMTPSA id 5556315A04D4; Thu, 29 Jan 2015 08:41:20 +0100 (CET)
Message-ID: <54C9E419.1070407@greenbytes.de>
Date: Thu, 29 Jan 2015 08:41:13 +0100
From: Julian Reschke <julian.reschke@greenbytes.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: Martin Thomson <martin.thomson@gmail.com>, Mark Nottingham <mnot@mnot.net>
CC: HTTP <ietf-http-wg@w3.org>
References: <1BA93C83-91E9-4E7D-88CE-ADC8C39091C6@mnot.net> <CABkgnnXhg55e5N2O8yZJpTbz4qSm0-KpVApyDha_snetrFqvMw@mail.gmail.com>
In-Reply-To: <CABkgnnXhg55e5N2O8yZJpTbz4qSm0-KpVApyDha_snetrFqvMw@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Received-SPF: pass client-ip=217.91.35.233; envelope-from=julian.reschke@greenbytes.de; helo=mail.greenbytes.de
X-W3C-Hub-Spam-Status: No, score=-3.0
X-W3C-Hub-Spam-Report: AWL=-3.023, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, URIBL_BLOCKED=0.001
X-W3C-Scan-Sig: lisa.w3.org 1YGjjS-0003R4-U1 7510be5e5742c8c27a8934d8220545a7
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Archived-At: <http://www.w3.org/mid/54C9E419.1070407@greenbytes.de>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28705
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

On 2015-01-29 01:21, Martin Thomson wrote:
> On 28 January 2015 at 14:45, Mark Nottingham <mnot@mnot.net> wrote:
>> Julian has proposed that <http://tools.ietf.org/html/draft-reschke-httpauth-auth-info-00> be adopted by this WG, with the aim of getting to LC quickly so that it can be referenced by other efforts.
>
> I'd like to see the fact that this is a *response* header field more
> prominent in the document.  The word "return" is used, but in this
> context, that's fairly ambiguous.

Will do.

(Which reminds me that in the list of considerations for new header 
fields in 7231, most apply to request header fields; we may want to 
restructure that text in the future)

> More fundamentally, I see a correlation issue if clients provide
> multiple *Authorization header fields.  The response they receive will
> contain some unaggregated name-value pairs in this header field.
>
>    "Its semantics are defined by the applicable authentication scheme."
>
> I don't know how that can be interpreted in the general sense since
> there isn't a way of identifying the corresponding scheme.
>
> And doesn't it need anti-collision machinery for the parameters?

See Yutaka's answer.

Best regards, Julian