[OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-cases-01
Jia Chen <chenjia@chinamobile.com> Fri, 14 August 2026 13:53 UTC
Return-Path: <chenjia@chinamobile.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 20C36129CBF6E for <oauth@mail2.ietf.org>; Fri, 14 Aug 2026 06:53:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786715620; bh=U0xk2wI2wC1NFql8jKnCl/eyNmtuOKqBgLym6hOE7oY=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=c3oi27XFp6v4Wc1/8CVYlLsEINPnKFMaKafLvzD6aLE+FyWemTgCz/HJaNbPtYjjK dW0O0/0n/w6X2q2QqGToJddndzD7+UlbYw3to2f4uy3oRvIIiarEhzRHYDCiK33HHM PGcb2ySPR7d3yJTP+ZK2igB4e7UbGeXcTuPVOjFo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.686
X-Spam-Level:
X-Spam-Status: No, score=-1.686 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_FONT_FACE_BAD=0.001, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=chinamobile.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DKNxcY5HcZFl for <oauth@mail2.ietf.org>; Fri, 14 Aug 2026 06:53:36 -0700 (PDT)
Received: from cmccmta8.chinamobile.com (cmccmta8.chinamobile.com [111.22.67.151]) by mail2.ietf.org (Postfix) with ESMTP id 099A1129CBF65 for <oauth@ietf.org>; Fri, 14 Aug 2026 06:53:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chinamobile.com; s=default; l=0; h=from:subject:message-id:to:cc:mime-version; bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=; b=tRQNsPkD9wfrpQsOGLewCLgdQyF0r+ovuaRPEnVIZUBiDYQWf/OZVp0osmZGbz9oQJQFL8znroJmJ D1ZNbjju6pP1o7O1BTkfqqIEaJO6ZfbJuZ6L9K3lUa32pgUi3pDbG0jWGfqc2FX8kLquCdZXkOPL71 JqS7BIbFAgBl6hUw=
X-RM-TagInfo: emlType=0
X-RM-SPAM-FLAG: 00000000
Received: from mail.dlp.master (unknown[10.188.0.87]) by rmmx-syy-dmz-app02-12002 (RichMail) with SMTP id 2ee26a7f1dd36b9-4852f; Fri, 14 Aug 2026 21:53:24 +0800 (CST)
X-RM-TRANSID: 2ee26a7f1dd36b9-4852f
Received: from wxh.mailtest (localhost [127.0.0.1]) by mail.dlp.master (Postfix) with ESMTP id DC39915A02CD for <oauth@ietf.org>; Fri, 14 Aug 2026 21:53:24 +0800 (CST)
Received: from spf.mail.chinamobile.com (unknown [10.230.70.214]) by mail.dlp.master (Postfix) with ESMTP id 316FA15A01B1 for <oauth@ietf.org>; Fri, 14 Aug 2026 21:53:17 +0800 (CST)
X-RM-TagInfo: emlType=0
X-RM-SPAM-FLAG: 00000000
Received: from [192.168.0.104] (unknown[183.241.54.14]) by rmsmtp-syy-appsvr10-12010 (RichMail) with SMTP id 2eea6a7f1dcb68d-ccdd0; Fri, 14 Aug 2026 21:53:16 +0800 (CST)
X-RM-TRANSID: 2eea6a7f1dcb68d-ccdd0
Content-Type: multipart/alternative; boundary="------------PPVWHwaBjt0zA54OhCQwcP0M"
Message-ID: <1ed3615c-dbe2-484d-be28-a3b24d67e177@chinamobile.com>
Date: Fri, 14 Aug 2026 21:53:34 +0800
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Meiling Chen <chenmeiling@chinamobile.com>, yaojk <yaojk@cnnic.cn>, jiangyuning2 <jiangyuning2@h-partners.com>, liuchunchi <liuchunchi@huawei.com>
References: <202608131756296188747@chinamobile.com>
Content-Language: en-US
From: Jia Chen <chenjia@chinamobile.com>
In-Reply-To: <202608131756296188747@chinamobile.com>
Message-ID-Hash: 5S4CFHT4WEKI746P7PZOSUMDUHA2QUCF
X-Message-ID-Hash: 5S4CFHT4WEKI746P7PZOSUMDUHA2QUCF
X-MailFrom: chenjia@chinamobile.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-cases-01
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/G3r5FAoQ0i5XjSKQvcm0xRgwCDA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Subject: UC3 and UC4 Dangling Requirements Review Results Hi Meiling and all, Following your call for a quality check on dangling requirements, I have reviewed the latest version of the draft (draft-chen-oauth-agent-authz-use-cases-02) with a focus on Use Case 3 and Use Case 4. Here are my findings. For Use Case 3 (Agent as User's Full Proxy to Access Third-Party Tools), the check passed. All six requirements listed in UC3 have corresponding entries in the Gap Analysis section. No dangling requirements were found. For Use Case 4 (Agent as User's Proxy to Access Operating System Resources), I found issues. Two requirements lack explicit corresponding analysis in the Gap Analysis. The first is "Task-Scoped Permissions". The Gap Analysis does not address why existing OS permission models cannot support task-bound lifecycle management or automatic revocation upon completion. The second is "Secure Privilege Escalation". The current Gap Analysis only mentions "Over-Privileging by Default" as a consequence, but it does not analyze why existing elevation mechanisms (such as sudo, UAC, or macOS authorization dialogs) are unsuitable or insecure for agent-initiated requests, nor why "just-in-time" and "user-approved" elevation are difficult to achieve in this context. I have prepared an issue on our GitHub repository to track this discrepancy. You can find it at the link below. https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/27 In the issue, I have also included proposed text for the missing Gap Analysis entries, which can be used directly for the -03 revision. Let me know if you would like me to draft a pull request with the proposed changes. Best regards, Jia Chen chenjia@chinamobile.com 在 2026/8/13 17:56, Meiling Chen 写道: > > Hi usecase co-authors, > > I'm writing to ask for your help with a crucial quality check as we > prepare for the |-03| submission of our agent authorization draft. > > Recently, we received some excellent and precise feedback from Morgan > on Use Case 6 (UC6). He pointed out a significant inconsistency: a > requirement had been added to the "Requirements" list, but its > corresponding analysis was completely missing from the "Gap Analysis" > section. This created a broken link for the reader and weakened the > argument for that use case. > > While I have already fixed the specific issue in UC6, this incident > highlights a potential systemic risk in our document. As the draft has > evolved and we've added or refined requirements, we may have > inadvertently created similar inconsistencies in other use cases. > > Call to Action: > > To prevent this from happening again and to strengthen the overall > quality of our draft, I am asking each of you to please review all use > cases (or at least the ones you are most familiar with) with a > specific focus on the following: > > Please verify that for every single requirement listed in a use case, > there is a corresponding and explicit entry or discussion in the > What's Missing (The Gap) or What Works (Partially) section for that > same use case. > > The goal is to ensure there are no "dangling requirements" where we > state a need but fail to analyze why the existing landscape (the gap) > makes it necessary. > > Please try to complete your review by this Friday. If you find any > discrepancies, please reply to this email thread or, even better, open > an issue on our GitHub repository so we can track it formally. > > Thanks for your help in ensuring the consistency and integrity of our > work. This proactive check will make the document much stronger for > the next round of community review. > > Best regards, > > Meiling > ------------------------------------------------------------------------ > chenmeiling@chinamobile.com
- [OAUTH-WG] draft-chen-oauth-agent-authz-use-cases… Meiling Chen
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Jia Chen
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Meiling Chen
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Blake Morrison
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Meiling Chen
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Blake Morrison
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Brian Vicente
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Meiling Chen
- [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-c… Blake Morrison