[OAUTH-WG] Re: New Version Notification for draft-chen-oauth-agent-authz-use-cases-02.txt
Mohamad Khalil Yossif <mohamad@yuthent.com> Wed, 12 August 2026 13:10 UTC
Return-Path: <mohamad@yuthent.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 88EA112888500 for <oauth@mail2.ietf.org>; Wed, 12 Aug 2026 06:10:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786540213; bh=sXp+RL/gs6w+dnjNGG0ZuoemxJ8ZLBM2hmERS0Wj+6Q=; h=From:Subject:Date:Cc:To; b=bH55KlGEvSItEb4i/60CLYhAzgdOmBgKIGd/3Gbc0CC9vvoIVOWqYyOSriIg5YXJE 9g/t17cv0SravaVfBAVYQY6jZrKp83wqUoD9M830tuQdqZsLvD90KVHWc6GTFiYF5X CobTVNEpi0gtpBBPsBrSUW2eT0WoS0wYvJ/GzKXA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=yuthent.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lSo5R-Z-ZNxw for <oauth@mail2.ietf.org>; Wed, 12 Aug 2026 06:10:13 -0700 (PDT)
Received: from out-zbxj-a91.jellyfish.systems (out-zbxj-a91.jellyfish.systems [198.54.127.91]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F3642128884F6 for <oauth@ietf.org>; Wed, 12 Aug 2026 06:10:12 -0700 (PDT)
Received: from MTA-05.privateemail.com (unknown [10.50.14.15]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by BSN-01.privateemail.com (Postfix) with ESMTPS id 4hKpk26bD2z3hhTB; Wed, 12 Aug 2026 09:09:46 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=yuthent.com; s=default; t=1786540186; bh=sXp+RL/gs6w+dnjNGG0ZuoemxJ8ZLBM2hmERS0Wj+6Q=; h=From:Subject:Date:Cc:To:From; b=P0yggN9vP+ARYAsXrC+gILUu4uQTBU0XM7co2l7zuNKcLGaBxs956KFvelczbiZ0I C8PfVP5GAgVF3ULn2fiBOn9GjAO7Lj20AyrF8XbxvK+iX2qVg3saaqzqIl1an7pXpf q+NoMtYpDTTnNwgaiHWwL1MqMcvFpVGEkRCd8Eq7bcOPlQtFW+LlrM7pv5u55eo14W ZiRuye0vOPBxH6w3iDdVtUHeQ+aQJuwVNpU5PNebOJWloMLMMpEUm9TZbbdzDeWTR4 Nl+QI6yDNH1BKA4coDNlvuRSof/IN2r30woFwLu7eIN0XPptB1ruSQsgxPeIAB9wkB 7piOqiNoKbScw==
Received: from mail.privateemail.com (K8S-PROD-WORKER-10 [46.210.154.254]) by mta-05.privateemail.com (Postfix) with ESMTPA id 4hKpjy74H6z3hhTJ; Wed, 12 Aug 2026 09:09:42 -0400 (EDT)
From: Mohamad Khalil Yossif <mohamad@yuthent.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_B95AD1FB-E8DF-4F9D-ACE1-3B76E6D8A74D"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
Message-Id: <F0148C3C-5896-4438-9ABB-FAAEFDD767B0@yuthent.com>
Date: Wed, 12 Aug 2026 16:09:30 +0300
To: chenmeiling@chinamobile.com
X-Mailer: Apple Mail (2.3864.700.51.1.1)
Message-ID-Hash: XBMY5L276USHQFDCIEWUMANJNB4HDLDT
X-Message-ID-Hash: XBMY5L276USHQFDCIEWUMANJNB4HDLDT
X-MailFrom: mohamad@yuthent.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: New Version Notification for draft-chen-oauth-agent-authz-use-cases-02.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/Eg4BX_LgyeJ1roMOs5tpEk8H5WI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
> Meiling, Yuning, > > Before I open a PR I need one thing settled, because the two answers > I have point in opposite directions and whichever I build will > conflict with the other. > > Yuning wrote on #15 yesterday that the scenario is better handled > inside UC1, that UC1 has already been updated to cover it, and that > #15 can be closed as merged. > > Meiling wrote this morning that a new standalone use case is the > clearest approach, and asked me to open a PR in that shape. > > I am happy to write either. Tell me which and I will send it. > > For what it is worth, my own view sits closer to Yuning's, and I want > to say why in case it helps you decide rather than just defer. > > The three points Yuning added to UC1 are the right ones - binding > approved constraints to later execution, preserving the admission > basis through to the endpoint, and verifying execution-time evidence > before the action takes effect. Those cover the gap. If they are in > UC1 already, a separate use case would restate the same requirements > under a different narrative, and the catalogue gets longer without > getting clearer. > > The one thing I would check before closing #15 is whether the UC1 > text keeps the distinction visible. The failure is not that the > agent lacked authority, and not that the wrong principal acted. The > agent had authority and the specific action was never approved by > anyone. If UC1 now carries that as a stated requirement rather than > as narrative context, then #15 is genuinely covered and I have no > objection to closing it. > > If instead you want it standalone because the point gets lost inside > UC1, that is a reason I would accept, and I will write it that way. > > On Gap C, the enrollment dependency, Yuning is right that it is > cross-cutting rather than UC1-specific. It sits under every use case > in the catalogue where a key is resolved to a person. If it is > useful I can propose short text for it as a cross-cutting concern > rather than attached to any single use case. > > Mohamad
- [OAUTH-WG] Fw: New Version Notification for draft… Meiling Chen
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… Meiling Chen
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… Meiling Chen