Re: [Webpush] vapid issue 24: supplementary data in tokens

Martin Thomson <martin.thomson@gmail.com> Sun, 10 July 2016 23:06 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: webpush@ietfa.amsl.com
Delivered-To: webpush@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58B5C12D0BD for <webpush@ietfa.amsl.com>; Sun, 10 Jul 2016 16:06:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tPf88H3oyHD7 for <webpush@ietfa.amsl.com>; Sun, 10 Jul 2016 16:06:14 -0700 (PDT)
Received: from mail-qk0-x22a.google.com (mail-qk0-x22a.google.com [IPv6:2607:f8b0:400d:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2AB24128E19 for <webpush@ietf.org>; Sun, 10 Jul 2016 16:06:14 -0700 (PDT)
Received: by mail-qk0-x22a.google.com with SMTP id o67so13738842qke.1 for <webpush@ietf.org>; Sun, 10 Jul 2016 16:06:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=zy5z7w46GgNLzTs1eWyWD43nBzXIaLkruQhVp7wcA5k=; b=BmS8fftsDfmFKnqEZxUNZjz58N4sdI4bLVoTxtf0NklhyeK3Qkf3RUJkfz0ia0Kp/B xPii0Bcz7/DKsXoECEA4P3vs+abyPY1+iBBbU7v2mfXeP8PPhxSo3ZhJoExxMkXfaB/r RYP4CEzfL+CErOVoPwmUyyGBfFZJ8r/eQodBazVYDXFHSjDg89mKPEdbh2jIeJB2JDnL JSaORbny21i22gpTRSUvxpBB5Uzu9IZhu1DC92XSg1ttTq3WBNwJGhLhRcdiFrwofLIi OGnWbiN6/bczDKodUASXQ9EBH6Ev7BxB1AsSwaf68hoXb1Y/WWDjiNU4xJ11v165qzmN 0onQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=zy5z7w46GgNLzTs1eWyWD43nBzXIaLkruQhVp7wcA5k=; b=lSkLfsTyBMO8s0kvPyJJnUgwlG8w/oeDjYNsMiXiSOhV87SUzaNFxL06nNuCHz35iY H6sVWJ/OdbxUW+rUT6MMQF3u9sjwAfyWGAX+kkmAwsu/8jytc0+9N1ienufxf2xrdNvE DT3Q1gz/+FcxyPjBB8YAUkP8Y9Z2OWOVcXOPtCIJbHY5BxpKEsjftPDEt9VswdskaL08 i5VynXwtnnes7Aon58v33W9FfxreqQgE14HM3Ykjy/5c9Ubr7ow+GhDO+s2qFO5vQAjh 9QQee2vvgLbImBLF/5jMPYT31CnoGzWZXUtUySRZDQBwBD0yABHzBanuWCTwl6kQgb9F a7bQ==
X-Gm-Message-State: ALyK8tLyE4bktqaBb5PlQGQi1T9V/3yLVjxFpPKMou7uALd7n2Z4KslP6mvG9I9yDXpAn/NqkheIeRaslgMASw==
X-Received: by 10.55.152.135 with SMTP id a129mr21129521qke.199.1468191973274; Sun, 10 Jul 2016 16:06:13 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.22.38 with HTTP; Sun, 10 Jul 2016 16:06:12 -0700 (PDT)
In-Reply-To: <c0903c40-a55d-0d33-267a-eb2ca620b067@mozilla.com>
References: <CABkgnnUkntEq66k+85zATwZHDKNMJ+NR_VZXa_jKCrDhhUSvPw@mail.gmail.com> <c0903c40-a55d-0d33-267a-eb2ca620b067@mozilla.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Mon, 11 Jul 2016 09:06:12 +1000
Message-ID: <CABkgnnWCshrNVHdNDN4omLLiWS9qoA_t9Aje_zq7=evUi-gsWQ@mail.gmail.com>
To: jr conlin <jconlin@mozilla.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/RjsESwRWhvGy9J2bZEBVkoWJlU4>
Cc: JR Conlin <jrconlin@mozilla.com>, "webpush@ietf.org" <webpush@ietf.org>
Subject: Re: [Webpush] vapid issue 24: supplementary data in tokens
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Jul 2016 23:06:15 -0000

PR up:
https://github.com/webpush-wg/webpush-vapid/pull/25

On 2 July 2016 at 02:08, jr conlin <jconlin@mozilla.com> wrote:
> I think it's absolutely fine to point out the additional claims. It may
> also be a good idea to provide some guidance about what name prefix to
> use to avoid potential conflicts should this header be compounded like
> the Crypto-Key header. (e.g.

The advice in RFC 6648 is probably good here.  JWT has a registry if
people want to coordinate things.

> It may also be worth noting that some servers (like apache) limit the
> maximum acceptable size of headers to 8K, so it's best not to go too
> nuts with the amount of extra data you're storing.

Yes, good advice.