[OAUTH-WG] Re: Genart last call review of draft-ietf-oauth-browser-based-apps-22
Aaron Parecki <aaron@parecki.com> Tue, 04 February 2025 01:34 UTC
Return-Path: <aaron@parecki.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6EC40C151082 for <oauth@ietfa.amsl.com>; Mon, 3 Feb 2025 17:34:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=parecki.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KcrsjdyzkSQu for <oauth@ietfa.amsl.com>; Mon, 3 Feb 2025 17:34:19 -0800 (PST)
Received: from mail-vk1-xa2f.google.com (mail-vk1-xa2f.google.com [IPv6:2607:f8b0:4864:20::a2f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 42543C15106B for <oauth@ietf.org>; Mon, 3 Feb 2025 17:34:19 -0800 (PST)
Received: by mail-vk1-xa2f.google.com with SMTP id 71dfb90a1353d-5161d5b8650so1419275e0c.3 for <oauth@ietf.org>; Mon, 03 Feb 2025 17:34:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=parecki.com; s=google; t=1738632858; x=1739237658; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=W5FAEBQ3TaL4ZF7bjQXdNGgLYLJG0Fd123x/A5XvaeY=; b=BZ5VtpTwxFyixu7AdMo0cr4onEPkWfQdtl1sRnWDf+iIrYLhwK22bnzOMeOO7fVgyA xv4yeOiKFQ9b832nqf41k5AeTEccgIv3sylzQ+X5YGt33QnIn7HzmpFLzs5P5UdySJBt 7ylvDwCkICEj27/gw95D58xnjpZQV0ast6I7EwMQXknGsAgLrV9G0Ew3i8cM57hrZ84n i6yeeEl8Juv5/ELMB48niFjMbi4xug6BBhUwpH/1MvB847/uVDdsutv8KBU6Ho7PZKOa z+oT16I+Ws8RedQTa4L071xJRZd/56Ks777x6Ck6rfOlfLNG9qcmmTe2pxWxHj6prTb0 C96A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1738632858; x=1739237658; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=W5FAEBQ3TaL4ZF7bjQXdNGgLYLJG0Fd123x/A5XvaeY=; b=DykWXhdcXL2fuVIaLgf6u03OdYZYPoTMFD85LxVGgsakCclQc0gffp7GCWBZJ6CMxL ZNzNhCumdWBGC4LEqgson59kKzq4DAmrmYR8d5QoeYnTxJjGO4J0UogJu5FXdIta1gHA UTEuWJtLXJBagVGTggU7ctqgs++c0lcWLain1szDwWfe0FreSGydeUdtGtSGoJTYwi3F GwOYQl6z8PskDMjObWIUY4w3cRAkQqrsLEnTeWLaiEbyspnggU0V7Hn+03komQlGSsKN ognDCP/94kymukeHplz9q3Jg2g+MjlUWb7lR2RBz58BkhBoeWHCmncgs0MiCAHr1ezPi oUFQ==
X-Forwarded-Encrypted: i=1; AJvYcCVXLvcCN3acgHrXg3hCMNJF5GUV/ekBNW+7zRtrWhOBF9Codyx6/Y9XNabyytcecTKPGgpfMQ==@ietf.org
X-Gm-Message-State: AOJu0Yz9ZqzvJnoW9Efpmn0ErnI6cNforgBLX87Ct34TOjI9KNeUh3OW VNs5z5asM2GLBoV2rl+xCki1OVUI8Y4PBBA9tBxglgQikf/QpC975S847ZtLgg==
X-Gm-Gg: ASbGncvp+emQSlhCEgI2NxWqy3lPcCEMlF/Tqt08lqqdZh6jtrbsKqD0rtrgfQdYtX2 ou0tiP8yfit36YO8Ty8s5hx9mW4OIVkR0/JnB/L09iBZLmxs/G7YDRlWLdOWiRvhiJRGa5vH27N LpjledudGOfsTC+oafRTU2XDim2B5tKCLfUzhlH62vEF1XiweIJzfmfcAb4Baxp2DkWNcF7LYM2 j2qiA0WbK+5oVFZL0FtXdwQ1oe/Kcxct5oGw01cEjp5bxMN7GTqD/jDpG5ugNqB/vnhWZ6pM4rx 0cDtS4KFp9EBL6nT+YjlPW1WQ2TPK9k+SMjuP8+WamSbILoARA==
X-Google-Smtp-Source: AGHT+IF/E3UMlAYcIyO0yEG9DTqu47DQj/a0wER6FgWxlBtR/fZXqI3F8m2B45Eby3o6EyMhwDuRnQ==
X-Received: by 2002:a05:6102:3911:b0:4b2:c105:dc40 with SMTP id ada2fe7eead31-4b9a4f23df1mr17751148137.8.1738632858019; Mon, 03 Feb 2025 17:34:18 -0800 (PST)
Received: from mail-vs1-f52.google.com (mail-vs1-f52.google.com. [209.85.217.52]) by smtp.gmail.com with ESMTPSA id ada2fe7eead31-4b9baa13ef1sm1827212137.3.2025.02.03.17.34.16 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 03 Feb 2025 17:34:17 -0800 (PST)
Received: by mail-vs1-f52.google.com with SMTP id ada2fe7eead31-4b11a11a4f0so1487402137.3; Mon, 03 Feb 2025 17:34:16 -0800 (PST)
X-Forwarded-Encrypted: i=1; AJvYcCUByqbVo15UKkW4Edq4lxPxt7AXs9lT80JiDdN/byC7GMUnG/g8HV98H9zMpS4LPXQhDou2qJnCpSSe@ietf.org, AJvYcCWUk0/vNsT8w3r7y+xAubJJYqaL5SuaT2PwJMsAIkiPLV2l/urlCrlNQw5PKDTeXPec5ylOjfG4GT72q9J9cHOvkPObVeExDs0/3P98xll3m4tXEhZNc7k=@ietf.org, AJvYcCXkY3wRWw2VAYfzMOKQiLiEpoh2x8XXn9mQLVCxTFpvqDNGDyocG6mH5wce5DWP4nxMjoV96Mo=@ietf.org
X-Received: by 2002:a05:6102:5786:b0:4b6:3700:d74a with SMTP id ada2fe7eead31-4b9a4d26fc9mr21457696137.0.1738632856209; Mon, 03 Feb 2025 17:34:16 -0800 (PST)
MIME-Version: 1.0
References: <173790446598.811797.1537736030508626353@dt-datatracker-5584d84fb4-tg2td>
In-Reply-To: <173790446598.811797.1537736030508626353@dt-datatracker-5584d84fb4-tg2td>
From: Aaron Parecki <aaron@parecki.com>
Date: Mon, 03 Feb 2025 17:34:05 -0800
X-Gmail-Original-Message-ID: <CAGBSGjoxXiwC=O72YiXd0GKkpk7roB_8PYQnReWP2-dGH-uQGQ@mail.gmail.com>
X-Gm-Features: AWEUYZn1cpcTofyaTsOKedUSLQXkUUN857iRHx7Op5mIGmlDLaXJeNN4yFy0ORA
Message-ID: <CAGBSGjoxXiwC=O72YiXd0GKkpk7roB_8PYQnReWP2-dGH-uQGQ@mail.gmail.com>
To: Thomas Fossati <thomas.fossati@linaro.org>
Content-Type: multipart/alternative; boundary="000000000000ca1ad2062d470119"
Message-ID-Hash: 5QJ5ZJKXLLNUJOEEDDST4UUZ2OHWJ5M7
X-Message-ID-Hash: 5QJ5ZJKXLLNUJOEEDDST4UUZ2OHWJ5M7
X-MailFrom: aaron@parecki.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: gen-art@ietf.org, draft-ietf-oauth-browser-based-apps.all@ietf.org, last-call@ietf.org, oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: Genart last call review of draft-ietf-oauth-browser-based-apps-22
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/eK-22dh72bKx7C42ZcMd1iA1LmY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Thanks for your edits Thomas! I've merged the PR. As for your BCP question, I am not totally certain about the implications of including it in BCP212, or whether it should be part of the new BCP240, or an entirely new BCP. I tried finding details about this in the various process RFCs/BCPs but I can't find an explanation. I've noted your comment about the "scenario" language as issue #68 to follow up on later. Thanks! Aaron On Sun, Jan 26, 2025 at 7:14 AM Thomas Fossati via Datatracker < noreply@ietf.org> wrote: > Reviewer: Thomas Fossati > Review result: Ready with Nits > > I am the assigned Gen-ART reviewer for this draft. The General Area > Review Team (Gen-ART) reviews all IETF documents being processed > by the IESG for the IETF Chair. Please treat these comments just > like any other last call comments. > > For more information, please see the FAQ at > > <https://wiki.ietf.org/en/group/gen/GenArtFAQ>. > > Document: draft-ietf-oauth-browser-based-apps-22 > Reviewer: Thomas Fossati > Review Date: 2025-01-26 > IETF LC End Date: 2025-02-04 > IESG Telechat date: Not scheduled for a telechat > > Summary: > > This is a BCP for browser-based apps that use OAuth 2.0. > It's a companion to BCP212, which contains similar recommendations for > OAuth 2.0 native apps. > > This document is very clearly written, exhaustive, and well-organised. > From a Gen-ART perspective, it's ready to ship. > Many thanks to the editors and the oauth WG. > > One question for the editors and WG regarding the BCP status: is > this doc going into BCP212 or does it get its own BCP number? > > Major issues: none > > Minor issues: none > > Nits/editorial comments: > > One editorial nit regarding the use of the term "scenario" in sentences > like: > > "scenarios that attackers can use" > "[...] scenarios that an attacker can execute" > > To my (non-native) ears, to "use/execute a scenario" sounds a bit > weird :-) Maybe "attack _strategies_ that an attacker can _exploit_"? > > Apart from that, I have packed a bunch of small fixes into a PR [1]. > > [1] https://github.com/oauth-wg/oauth-browser-based-apps/pull/65 > > > > >
- [OAUTH-WG] Genart last call review of draft-ietf-… Thomas Fossati via Datatracker
- [OAUTH-WG] Re: Genart last call review of draft-i… Aaron Parecki