The mission of this working group is to define a mechanism to annotate Web forms to support both better client-side credential management, and integration of form-based input mechanisms with protocol-level authentication mechanisms such as HTTP Digest Authentication.

Background and Scope

Authentication on the Web is, today, largely based on the entry of user names and passwords through HTML forms, and their submission through HTTP POST. Session management on the basis of browser cookies or hidden form fields is then used to keep authentication state for further transactions. Existing mechanisms for HTTP Authentication [RFC 2617] are ignored in these scenarios.

To assist users in these situations, web user agents are typically able to cache user names and passwords. This caching is based on heuristic recognition of those form fields that are used for authentication information; consequently, they fail in slightly a-typical situations.

This working group is chartered to develop a mechanism for annotating HTML forms, to

Key requirements include:

This Working Group is not chartered to develop new authentication protocols.


The group should deliver:


W3C Groups

The Web Security Context Baseline Working Group should coordinate its activities with other relevant W3C Working Groups, specifically:

Web Application Formats
The mission of the W3C Web Application Formats Working Group is to develop specifications that enable improved client-side application development on the Web. This includes the development of languages for applications, especially user interfaces.
W3C Form work
This group will coordinate with related work in other W3C Activities through the Hypertxt Coordination Group.

External Groups

The following is a tentative list of external bodies that the Working Group should collaborate with:

Internet Engineering Task Force
The IETF community is, as of fall 2006, considering new work on enhancements in Web Authentication. It is expected that any working groups emerging from these considerations will need to liaise with this working group.
The OASIS Security Services Technical Committee is chartered to define and maintain a standard, XML-based framework for creating and exchanging security information between online partners.
Liberty Alliance
Liberty Alliance is developing an open standard for federated network identity that supports all current and emerging network devices.

