Re: [OAUTH-WG] WGLC Review of PAR

Mike Jones <Michael.Jones@microsoft.com> Sat, 29 August 2020 00:22 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0837D3A0E75 for <oauth@ietfa.amsl.com>; Fri, 28 Aug 2020 17:22:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mbFKkUVFJQd2 for <oauth@ietfa.amsl.com>; Fri, 28 Aug 2020 17:21:59 -0700 (PDT)
Received: from NAM06-DM3-obe.outbound.protection.outlook.com (mail-eopbgr640113.outbound.protection.outlook.com [40.107.64.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 200ED3A0E74 for <oauth@ietf.org>; Fri, 28 Aug 2020 17:21:58 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ZCX4kjcoZMLRQY5C5g4xXZAe7KYqQjAWSMxFQtLD3L7TY+e0sRtb2mU0qv/J7bB3+CnG2szsnR2aT1DTgCfvS8OM/qOO+Sof4/JM4L2TjI0RAkbSpzvuEV0+sprpOTCihybbRGZ9vLZxB2qhy7yLKAI3+/TzAr587x5jPHKcDBsQ3/6axu+Kmkq0VB3yH3XDz478nmtgG573++HH8616Jzo3Xvkk6LHG+DguVxA7XTcDqHZzs/wTXx/6/NmwPBBjNz9Iavl2Bze0RFr/glyC2BE6sekyM25pqm3o/nAFG2ytlUYV37ZHXRMAX4IPKgLk+rwjtNBhQnLxvjHaefqWzQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X5cXwrMZ/wCUyvHHelpRZayPgctFWfVPG3t8EmC0KxM=; b=H4fMBqjMVBdIWVnRLpfEPzP6VIVUFLn9IWAm0stYOqCqrhcCK+SxnoszHjivZU5176QdTj71tagbiqsa8tkMGdtW+LfUIOB8wyACTZfvqdF5IUQWvoV3eXECBebCmgl5eqXq+E6x9OBTSHAQrcdN3yRPNV61A62RnjlZTLLpFfo/d0mVF/MSUZSPj6F8xpFWnM+0SFwAqkah1YtOGtJEDzGzvrtOnLywrzGXgmSgj/4Rie9eAXifTaynoDlLmLrvaf6gLQvqVLvzAfzYofjVGzgHp7BpZTJ+tX2K4UEEnIr4Cq75JYeV828d7aisEZjrq12C509aVupo0pA6hngNmA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X5cXwrMZ/wCUyvHHelpRZayPgctFWfVPG3t8EmC0KxM=; b=ba0NrGoXx7Y0DJuRsH4qUbMkB0/g9pPvEzjZTACwOIEP0FaRPa7o5dK74EqzLGGHHKEFminTcKvHQby2FIgv+/BrPKhMs628oUFP+tMqanDb977zp7rxt7kqUIKSTqvTdxCrBgxZiAXZ8V1tYYIuAlSuWuSi2bkTseRGHa8k+kw=
Received: from (2603:10b6:5:21c::8) by DM6PR00MB0831.namprd00.prod.outlook.com (2603:10b6:5:20d::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3375.0; Sat, 29 Aug 2020 00:21:56 +0000
Received: from DM6PR00MB0684.namprd00.prod.outlook.com ([fe80::201a:3483:38b9:fe9f]) by DM6PR00MB0684.namprd00.prod.outlook.com ([fe80::201a:3483:38b9:fe9f%3]) with mapi id 15.20.3375.000; Sat, 29 Aug 2020 00:21:56 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: dick.hardt <dick.hardt@gmail.com>, Justin Richer <jricher@mit.edu>
CC: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>, oauth <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] WGLC Review of PAR
Thread-Index: AdZ9mmVYNw8LyZ0tRL6OVh0+8bIpvg==
Date: Sat, 29 Aug 2020 00:21:56 +0000
Message-ID: <DM6PR00MB0684BEBE5FAB3E2C483298B4F5531@DM6PR00MB0684.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=b99b2b34-cc9d-425d-bcc4-f7ef39d0bf06; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2020-08-29T00:20:23Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [50.47.94.10]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 23368013-6d0e-4a0c-4144-08d84bb189cf
x-ms-traffictypediagnostic: DM6PR00MB0831:
x-ld-processed: 72f988bf-86f1-41af-91ab-2d7cd011db47,ExtAddr
x-microsoft-antispam-prvs: <DM6PR00MB0831C88CF5126C4535D5A72EF5531@DM6PR00MB0831.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: zoOBbQZ5rkk6KR6dxKzXCOXlM0fwy1+t/kOTg87q6CLJ6seNs+GrMQS/NP9BctLCMXzILjxOkJmLZJFNVwtFikpYz0wP/Rc0V2IZwbVxs/Zz59k9wxVBK87ld6X/jJWQlE3ciChJwDXgZgX0AzjMPkhofXRVK5DY/MY7B6HhqJazjbo820OWATJvzDp+YlD396JKtnOTS3aPIpWy39jOM+3FZs9EVVoSZmdXhEwq2RzA0RODi+kqtJhYzYDSI+nF736phcSkWnHzbuADu4cO50sLMwputa+P6mviJNICbQ2hgxsUSVFT3T77QWNJgc47hvHgoQ87aC3ZFHUSC4Z60yruv48pEN4ijwaMAlQ+YdJgN85iuBqAcM29LWiCr5b0QxvFd+0zPAaUwSH2tiLTwoAaEye3kuRRXf9ERHIY9BBzT4b2jE0PXndurK62fWiDeby8buQeS/i2uH6BqjMRjg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR00MB0684.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(39860400002)(396003)(346002)(376002)(136003)(366004)(66946007)(10290500003)(86362001)(166002)(2906002)(8990500004)(4326008)(66574015)(8936002)(76236003)(8676002)(83380400001)(76116006)(66476007)(66556008)(64756008)(71200400001)(33656002)(54906003)(110136005)(66446008)(6506007)(53546011)(26005)(186003)(52536014)(82960400001)(82950400001)(7696005)(9686003)(478600001)(55016002)(316002)(5660300002)(966005)(99710200001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: c9kBSzvAOMuYaDlwUFiS3IQpLlp5GohfeyEFQ7W3zE4xJSmNk0PMoLxHEB0fBR72NbsjqJl20hC6i6Y3FLsleCgsasFWHI28HZo0RbQCbybsrfT+N7DO/lSUCzTw58Dw8XCQvzyA4HtrLW3QdUxyPb0GqMawfEEU7pX6/cpo3d4V4bHgjK7AepArcPY+6qAnu+eYAKM0P13G5NlE9zk0uTTCcklgJ9gLxtxjuHtPb0Sb2BbE5g6uEQMP/kV3mDnJ/JWLeiQVKoaLKAc12dwqWp3HpVyldhbN9KdSWOnqHC0cXvfRZE5itaHDBfqPk5ow6y7q2jSoeVGQpKATICZbRsd8oksrI899becnidZsYfxsUYb3YbKVXupJr1bmcKn6/mlDyUChyZlnp6JGb1e7NM/I1Sys6lMp/mazIvsEpHGrg7+WD7WgZ8DCsjxU8FGjIPuGoeLsvoR3Wq6Z/AMf0oCaqb8RxC9hsZNrWLnty2IA+DXI2zOX0yYRBLInlUiA4if3IMnR0wOjgE5hOe+FhPThJKL3FhqMhQNfZCbK+7g+znKOA7MLcmGSNc4IhSG6zOwJTSY0xviDssYjXv57uYYA+mVKNqADTG20w9+rHNhAsBPm3tUCzIbptIbUi5nhs/QGKjAG6WYGUiF1bR/w7w==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DM6PR00MB0684BEBE5FAB3E2C483298B4F5531DM6PR00MB0684namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR00MB0684.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 23368013-6d0e-4a0c-4144-08d84bb189cf
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Aug 2020 00:21:56.4956 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: D4HVbtTvcuLY2hBnnTNViie7H2i2zdvNRrftGDTMfHv7zDk1CXPblPoomQSbaovz9t9QsMtTKi86ZIadIq2yMQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR00MB0831
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/-xk9rKJc3R-y_hSt5boodMhWJjc>
Subject: Re: [OAUTH-WG] WGLC Review of PAR
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 29 Aug 2020 00:22:03 -0000

I agree with Dick that it would be a mistake to make the URL one-time use.  It’s unenforceable and unnecessarily gets in the way of valuable deployment patterns.

From: OAuth <oauth-bounces@ietf.org> On Behalf Of Dick Hardt
Sent: Thursday, August 27, 2020 9:12 AM
To: Justin Richer <jricher@mit.edu>
Cc: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>rg>; oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] WGLC Review of PAR

That is not correct.

The authorization code one-time-use is directly between the client and the AS. The client has a number of mechanisms to ensure it only presents the authorization code to the AS once, such as a session that was set when the user started at the client.

In contrast, in a redirect from the client to the AS, the client loses control on how many times the user-agent loads the URL at the AS. Additionally, there is unlikely to be an active browser session at the AS, so the AS can not easily differentiate between a URL load from the same user, or different users. If one-time-use, one of them MUST fail. If the two requests happen to be from the same user (because of a reload, which the user did because the AS was slow to respond), there is no way for the AS to know which of the requests is the one that is current in front of the user. While the AS can internally ensure processing of the request once, one-time-use would dictate that it provides a failure message to one of the requests.

/Dick


ᐧ

On Thu, Aug 27, 2020 at 7:17 AM Justin Richer <jricher@mit.edu<mailto:jricher@mit.edu>> wrote:
We already have this same property with authorization codes, and it’s managed today reasonably well (in my opinion). If you submit the same request URI twice in the same browser (the refresh you’re talking about), it shouldn’t start two separate authorization requests, but it would be reasonable to detect that the same session attached to the same request URI value showed up twice and continue the session as appropriate.

None of this is in conflict with “one time use”, in my view, since you’re actively detecting the session and source of the value.

 — Justin


On Aug 26, 2020, at 6:16 PM, Dick Hardt <dick.hardt@gmail.com<mailto:dick.hardt@gmail.com>> wrote:

I think one-time use may be overly restrictive, and I don't think it is the property that we actually want.

Give the request URI is in a redirect from the browser, there is a good chance of a race condition where the same browser request is made more than once, for example, while the browser is loading the authorization URL at the AS, the user could refresh the page causing the authorization URL to be reloaded. Would the reload count as a second use? One could argue it either way.

What I think we want from what I understand, is the request URI MUST be unique so that there is no confusion on which request is being referenced.

I did not see anything about the expiry time of the request URI (but I did not look super hard). If that is not there, then I think the request URI MUST expire in a "short" period of time.



ᐧ

On Wed, Aug 26, 2020 at 1:45 PM Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org<mailto:40pingidentity.com@dmarc.ietf.org>> wrote:
Thanks Justin. Just a couple more responses to responses inline below (but with lots of content that needs no further discussion removed).

A TL;DR for the WG is that I'd like to get some wider feedback on the question of changing the one-time-use condition on the request_uri from a SHOULD to a MUST.

On Tue, Aug 25, 2020 at 4:57 PM Justin Richer <jricher@mit.edu<mailto:jricher@mit.edu>> wrote:
Hi Brian, just a couple responses inline where it seemed fitting. Thanks for going through everything!
 — Justin


On Aug 25, 2020, at 6:01 PM, Brian Campbell <bcampbell@pingidentity.com<mailto:bcampbell@pingidentity.com>> wrote:

Thanks for the review and comments Justin. Replies (or attempts thereat) are inline below.


On Wed, Aug 19, 2020 at 2:06 PM Justin Richer <jricher@mit.edu<mailto:jricher@mit.edu>> wrote:
I’ve done a full read through of the PAR specification, and here are my notes on it.


    ¶2: Of necessity, this spec mixes parameters in the authorization endpoint and token endpoint registries into a single request. Is there any danger of conflict between them? The registry holds them in one list but they could possibly have different semantics in both places..

I think that technically such danger does exist but that it's highly unlikely in practice. Especially because the only token endpoint parameters that are relevant to PAR are those that deal with client authentication (currently client_secret, client_assertion, and client_assertion_type). I'm also not sure what can reasonably be done about it given the way the registries are. I guess PAR could update the registration for those three (client_secret, client_assertion, and client_assertion_type) to also indicate authorization request as a usage location with some commentary that it's only for avoiding name collisions. And offer some guidance about doing the same for any future client auth methods being defined. But honestly I'm not sure what, if anything, to do here?

And yes it is super unfortunate that client auth and protocol parameters got mixed together in the HTTP body. I didn't cause that situation but I've certainly contributed to it and for that I apologize.

I think the only perfect solution is to go back in time and fix the registries with based on the last decade of knowledge in using them. :P

For this, I think maybe being very prescriptive about the fact that the only parameters from the token endpoint that are allowed here are those used for client authentication and that when they show up, they’re interpreted as in the token endpoint request not the authorization endpoint request. Does that work?

I think so, yes.. And will work on incorporating some text towards that end.



    I don’t see why a request URI with unguessable values isn’t a MUST for one-time-use, is there a reason?

The reason AFAIK was to not be overly prescriptive and allow for eventually consistent or not atomic storage of the data by not strictly requiring the AS to enforce one-time-use. Do you think that's too loose or could be worded/explained differently or better?

I do think it’s too loose and it should be a MUST, and the methods for enforcing that “MUST” are going to vary based on the deployments and implementations out there.


I'd be okay with making it a MUST but think maybe it'd be good to hear from a few more people in the WG before committing to that change.

Can I ask some folks to weigh in on this one? I'm leaning towards making the change barring objections.


CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited...  If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you._______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth