[GNAP] Weekly github digest (GNAP Weekly GitHub Activity Summary)

Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/Fp21oURVhs_9dDW_ne7gccAwPAE>
Subject: [GNAP] Weekly github digest (GNAP Weekly GitHub Activity Summary)
Events without label "editorial"

* ietf-wg-gnap/core-protocol (+1/-19/💬23)
  1 issues created:
  - Short term and long term RS user accounts (by Denisthemalice)

  19 issues received 23 new comments:
  - #322 Short term and long term RS user accounts (3 by Denisthemalice, jricher)
  - #298 Untrusted security-critical information from the Client (1 by jricher)
  - #292 Does a client instance really need to be identified by a unique key ? (3 by Denisthemalice, aaronpk, fimbault)
  - #290 Checks needed to defeat user collaborative attacks are unfortunately out of the scope of the document (1 by jricher)
  - #289 Bearer tokens should not be supported or be deprecated (1 by aaronpk)
  - #288 Since both rights and resource locations must be disclosed to the AS, the AS can act as Big Brother (1 by fimbault)
  - #287 About the locations field (1 by jricher)
  - #285 The diagram of the exchanges is mandating a pre-configuration between each pair of AS/RS (1 by fimbault)
  - #253 Discuss MTLS deployment differences (1 by jricher)
  - #249 Privacy Considerations for Subject Identifiers (1 by aaronpk)
  - #221 DID as identifier (1 by fimbault)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/221 [Needs Text] 
  - #215 User choice and consent, and user notice (1 by jricher)
  - #214 Trust relationships (1 by fimbault)
  - #175 GNAP for Custodial SSI Wallets (1 by jricher)
  - #169 User-to-user delegation (1 by fimbault)
  - #168 message based interaction / DIDComm (1 by fimbault)
  - #154 Common means to dereference key references (1 by aaronpk)
  - #149 Special label for access token used for continuation (1 by jricher)
  - #133 Privacy considerations (1 by aaronpk)

  19 issues closed:
  - Terminology: definition for "key proof" https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/159 [Design] 
  - Define which "resources" fields are optional https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/167 
  - message based interaction / DIDComm https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/168 
  - User-to-user delegation https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/169 
  - GNAP for Custodial SSI Wallets https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/175 
  - Trust relationships https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/214 
  - User choice and consent, and user notice https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/215 
  - DID as identifier https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/221 [Needs Text] 
  - Privacy considerations https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/133 
  - Privacy Considerations for Subject Identifiers https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/249 
  - Discuss MTLS deployment differences https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/253 
  - How can an AS determine "what is needed" to fulfill the request ? https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/264 
  - The diagram of the exchanges is mandating a pre-configuration between each pair of AS/RS https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/285 
  - About the locations field https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/287 
  - Since both rights and resource locations must be disclosed to the AS, the AS can act as Big Brother https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/288 
  - Bearer tokens should not be supported or be deprecated https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/289 
  - Checks needed to defeat user collaborative attacks are unfortunately out of the scope of the document https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/290 
  - Does a client instance really need to be identified by a unique key ? https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/292 
  - Token Management functions are over-engineering https://github.com/ietf-wg-gnap/gnap-core-protocol/issues/293 

* ietf-wg-gnap/gnap-resource-servers (+0/-4/💬1)
  1 issues received 1 new comments:
  - #2 The Abstract and the Introduction should be aligned (1 by jricher)
    https://github.com/ietf-wg-gnap/gnap-resource-servers/issues/2 [Editorial] 

  4 issues closed:
  - RS Token derivation https://github.com/ietf-wg-gnap/gnap-resource-servers/issues/23 
  - The Abstract and the Introduction should be aligned https://github.com/ietf-wg-gnap/gnap-resource-servers/issues/2 [Editorial] 
  - “RS-Facing API” versus “AS-Facing API” https://github.com/ietf-wg-gnap/gnap-resource-servers/issues/39 [Pending Close] 
  - Trust relationships between a RS and an AS https://github.com/ietf-wg-gnap/gnap-resource-servers/issues/7 

Pull requests
* ietf-wg-gnap/core-protocol (+9/-3/💬22)
  9 pull requests submitted:
  - Replace remaining occurrences of "callback" (by pq2)
  - Add contributor (by jricher)
  - inline definition of "key proof" (by jricher)
  - Add link to authorization processing section in diagram. (by jricher)
  - Add security considerations for message-level signatures (by jricher)
  - Replace "split field" with "split flag" (by pq2)
  - Fix description of interaction start modes (by pq2)
  - Remove 'bearer' (by pq2)
  - Replace 'push' with 'finish' (by pq2)

  11 pull requests received 22 new comments:
  - #321 Replace remaining occurrences of "callback" (1 by netlify)
  - #320 Add contributor (1 by netlify)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/320 [Editorial] 
  - #319 inline definition of "key proof" (1 by netlify)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/319 [Editorial] 
  - #318 Add link to authorization processing section in diagram. (1 by netlify)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/318 [Editorial] 
  - #317 Add security considerations for message-level signatures (1 by netlify)
  - #316 Replace "split field" with "split flag" (3 by jricher, netlify, pq2)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/316 [Editorial] 
  - #315 Fix description of interaction start modes (1 by netlify)
  - #314 Remove 'bearer' (2 by jricher, netlify)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/314 [Editorial] 
  - #313 Replace 'push' with 'finish' (1 by netlify)
  - #306 initial draft of trust relationships (9 by Denisthemalice, agropper, fimbault)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/306 [Pending Merge] 
  - #304 Security Considerations (1 by fimbault)
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/304 [Pending Merge] 

  3 pull requests merged:
  - inline definition of "key proof"
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/319 [Editorial] 
  - Add link to authorization processing section in diagram.
    https://github.com/ietf-wg-gnap/gnap-core-protocol/pull/318 [Editorial] 
  - Add security considerations for message-level signatures

* ietf-wg-gnap/gnap-resource-servers (+1/-0/💬1)
  1 pull requests submitted:
  - Change apostrophes to backticks (by pq2)

  1 pull requests received 1 new comments:
  - #44 Change apostrophes to backticks (1 by netlify)

Repositories tracked by this digest:
* https://github.com/ietf-wg-gnap/core-protocol
* https://github.com/ietf-wg-gnap/gnap-resource-servers