Re: [OAUTH-WG] register prefixes as opposed to full parameter names

Marius Scurtescu <mscurtescu@google.com> Thu, 01 July 2010 21:59 UTC

Return-Path: <mscurtescu@google.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2A4D13A6A53 for <oauth@core3.amsl.com>; Thu, 1 Jul 2010 14:59:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.609
X-Spam-Level:
X-Spam-Status: No, score=-101.609 tagged_above=-999 required=5 tests=[AWL=0.368, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8w5qUphKNSp3 for <oauth@core3.amsl.com>; Thu, 1 Jul 2010 14:59:11 -0700 (PDT)
Received: from smtp-out.google.com (smtp-out.google.com [74.125.121.35]) by core3.amsl.com (Postfix) with ESMTP id C4FD63A68BB for <oauth@ietf.org>; Thu, 1 Jul 2010 14:59:10 -0700 (PDT)
Received: from wpaz29.hot.corp.google.com (wpaz29.hot.corp.google.com [172.24.198.93]) by smtp-out.google.com with ESMTP id o61LxKZt003749 for <oauth@ietf.org>; Thu, 1 Jul 2010 14:59:20 -0700
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=google.com; s=beta; t=1278021561; bh=5X7ri97GSE3AmANtR4mp40I2Xp0=; h=MIME-Version:In-Reply-To:References:From:Date:Message-ID:Subject: To:Cc:Content-Type:Content-Transfer-Encoding; b=mwxevTtxh1t0ihY1IIkZFPWAWGO90FGS3Us8mziF7L7RVBAc07SrxUTQuhVTGhe3q I+eY7ZUeA9BsmyVYJB0lg==
DomainKey-Signature: a=rsa-sha1; s=beta; d=google.com; c=nofws; q=dns; h=mime-version:in-reply-to:references:from:date:message-id: subject:to:cc:content-type:content-transfer-encoding:x-system-of-record; b=TZ4EDJJqctcev1h+mC+Qdp7sOhox1Ji3LPo/S9uZzZZW8O9Hlf+thrrMQ52GESHvB wFjLrFnGKoI7w/9URul1A==
Received: from gyg8 (gyg8.prod.google.com [10.243.50.136]) by wpaz29.hot.corp.google.com with ESMTP id o61LxJYL003519 for <oauth@ietf.org>; Thu, 1 Jul 2010 14:59:19 -0700
Received: by gyg8 with SMTP id 8so1753173gyg.16 for <oauth@ietf.org>; Thu, 01 Jul 2010 14:59:19 -0700 (PDT)
Received: by 10.101.134.9 with SMTP id l9mr136697ann.184.1278021559220; Thu, 01 Jul 2010 14:59:19 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.101.132.22 with HTTP; Thu, 1 Jul 2010 14:58:59 -0700 (PDT)
In-Reply-To: <90C41DD21FB7C64BB94121FBBC2E72343B3ED4C528@P3PW5EX1MB01.EX1.SECURESERVER.NET>
References: <AANLkTin7zWi7m_evTgI49JKXLPuVqYBFlCR8CtSYRKDM@mail.gmail.com> <90C41DD21FB7C64BB94121FBBC2E72343B3ED4C4E2@P3PW5EX1MB01.EX1.SECURESERVER.NET> <AANLkTik_f9MRWIK4kZ3c5pANtPloOsxyzYeL6bqMFhbs@mail.gmail.com> <90C41DD21FB7C64BB94121FBBC2E72343B3ED4C528@P3PW5EX1MB01.EX1.SECURESERVER.NET>
From: Marius Scurtescu <mscurtescu@google.com>
Date: Thu, 01 Jul 2010 14:58:59 -0700
Message-ID: <AANLkTilrV6thlDrCx1yVVtpRqYWd7A4wAn6kCrwCO6T6@mail.gmail.com>
To: Eran Hammer-Lahav <eran@hueniverse.com>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
Cc: OAuth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] register prefixes as opposed to full parameter names
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Jul 2010 21:59:12 -0000

On Thu, Jul 1, 2010 at 2:52 PM, Eran Hammer-Lahav <eran@hueniverse.com> wrote:
>
>> -----Original Message-----
>> From: Marius Scurtescu [mailto:mscurtescu@google.com]
>> Sent: Thursday, July 01, 2010 2:21 PM
>
>> >> 2. Greatly reduce the chances of a conflict with a query parameter
>> >> used by an authz server endpoint or client redirect_uri.
>> >
>> > There should not be any conflict. Either it has been registered or uses x_.
>>
>> There can be. Here is the example I gave earlier in another thread.
>> MediaWiki uses the 'title' parameter. Some OAuth extension may register
>> and use this same name and this will prevent MediWiki from being able to
>> support that extension.
>
> I think this discussion (which we spent many days on already) boils down to a philosophical approach to the level a new protocol should accommodate the broken environment in which it is expected to be deployed.
>
> I think MediaWiki should change the way it treats the OAuth endpoints to isolate them from the rest of the platform. When receiving an OAuth request (with such an OAuth 'title' parameter), the platform can rename all the OAuth parameters to oauth_ internally and proceed to add its own parameters without conflicts.

When receiving an OAuth request MediaWiki will have two title
parameters, the damage is already done.


> While this approach might not be trivial, it is clearly possible. I think there is a larger question of how OAuth is used in a MediaWiki installation, and how it can accommodate some of the other requirements such as SSL.
>
> I do not consider making MediaWiki's deployment of 2.0 easier an important consideration.

MediaWiki is just an example. Drupal is another. My guess is that most
PHP frameworks have this issue.


>> >> Cons:
>> >>
>> >> 1. Slightly longer parameter names.
>> >
>> > Also, messy, ugly, opens the door to extensions without review.
>>
>> I don't get the last part, skipping reviews. As for beauty, that's relative ;-)
>
> If we approve a blanket "prefix_" extension, we lose the ability to review individual parameters within that prefix.

I think you mentioned that the review is meant to prevent name
conflicts, nothing else.


Marius