W3C

- DRAFT -

Weekly Forms WG Teleconference

12 Dec 2007

Agenda

See also: IRC log

Attendees

Present
John_Boyer, wellsk, Nick_van_den_Bleeken, unl, Leigh_Klotz, +34.91.2.aaaa, +49.308.3.aabb, jturner, ebruchez, Rafael, Raman
Regrets
MarkB, Charlie, Steven
Chair
John
Scribe
Leigh

Contents


 

 

<John_Boyer> Scribe: Leigh

<John_Boyer> scribenick: klotz

<Nick> zakim ??P8 is unl

<unl> hey nick, how do you know?

<Nick> you just joined after keith

<Nick> raman it is keith

<John_Boyer> Agenda: http://lists.w3.org/Archives/Public/public-forms/2007Dec/0017.html

<Nick> John, you are all static

<Nick> http://lists.w3.org/Archives/Public/public-forms/2007Dec/0015.html

<Nick> http://lists.w3.org/Archives/Public/public-forms/2007Dec/0012.html

Access Control WD Review

<John_Boyer> 28<http://lists.w3.org/Archives/Public/public-forms/2007Dec/0015.html>

<Nick> klotz: It will affect us, it solves security problems with GET, PUT

<Nick> klotz: Lets you configure what resources can be reached from this resource, using HTTP headers and PI's

<Nick> klotz: It looks a bit weak, and will not enable mashups, because these others URI's need to specify what is allowed

<Nick> klotz: We could ask if they use XForms as a test case

<Nick> klotz: I want some input from implementers, bcz I'm not a real expert on this

<Nick> klotz: They are moving forward fast, so the time to respond is limited

<Nick> klotz: the problem is that the client checks the security, no tickets, tokens, so it is weak

<Nick> john: how can they increase their security

<Nick> klotz: I don't want to comment on this, it seems that this is what they want to solve

<Nick> klotz: XForms implementations should check if they could implement it and give feedback

<Nick> klotz: explains how it works

<Nick> klotz: before a POST you do a get to check security

<Nick> john: what if the server doesn't implement the GET

<Nick> klotz: then you can not access this resource

<Nick> john: do they only check if you try to cross a domain boundary

<Nick> klotz: yes indeed

<Nick> John: If we implement it we should do a GET before a POST

<Nick> John: So we need to consider it in a future version in the submission model

<Nick> klotz: we need ensure that if it is done, we can incorporate it

<Nick> John: Do you want to post your e-mail

<Nick> klotz: I want an implementer to look at it

<Nick> klotz: I think MarkB or Aaron should look at it

<Nick> John: We could ask Aaron to join a future call

<Nick> klotz: I will send a response and say that we are working on it

<Nick> john: Would you cross post it to www-forms

<Nick> klotz: What I have small points not appropriate for ww-forms

<John_Boyer> http://lists.w3.org/Archives/Public/public-forms/2007Dec/0008.html

Future Features

<scribe> ACTION: Leigh Klotz to post updated message on access-control to comments list, and indicate that we continue to study the isssue. http://lists.w3.org/Archives/Public/public-forms/2007Dec/0012.html [recorded in http://www.w3.org/2007/12/12-forms-minutes.html#action01]

<trackbot-ng> Created ACTION-436 - Klotz to post updated message on access-control to comments list, and indicate that we continue to study the isssue. http://lists.w3.org/Archives/Public/public-forms/2007Dec/0012.html [on Leigh Klotz, Jr. - due 2007-12-19].

Thanks, Nick.

<John_Boyer> http://www.w3.org/TR/xforms-11-req/

<jturner> schnitz here, belated regrets, and happy X-mas

RESOLUTION: We add something like "simplify and provide use cases for UI events and model events" on the list of five things for XForms 1.2.

Summary of Action Items

[NEW] ACTION: Leigh Klotz to post updated message on access-control to comments list, and indicate that we continue to study the isssue. http://lists.w3.org/Archives/Public/public-forms/2007Dec/0012.html [recorded in http://www.w3.org/2007/12/12-forms-minutes.html#action01]
 
[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.128 (CVS log)
$Date: 2007/12/12 17:04:34 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.128  of Date: 2007/02/23 21:38:13  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: RRSAgent_Text_Format (score 1.00)

Succeeded: s/XForms 1.1/XForms 1.2/
Found Scribe: Leigh
Found ScribeNick: klotz

WARNING: 4 scribe lines found (out of 131 total lines.)
Are you sure you specified a correct ScribeNick?

Default Present: John_Boyer, wellsk, Nick_van_den_Bleeken, unl, Leigh_Klotz, +34.91.2.aaaa, +49.308.3.aabb, jturner, ebruchez, Rafael, Raman
Present: John_Boyer wellsk Nick_van_den_Bleeken unl Leigh_Klotz +34.91.2.aaaa +49.308.3.aabb jturner ebruchez Rafael Raman
Regrets: MarkB Charlie Steven
Agenda: http://lists.w3.org/Archives/Public/public-forms/2007Dec/0017.html
Got date from IRC log name: 12 Dec 2007
Guessing minutes URL: http://www.w3.org/2007/12/12-forms-minutes.html
People with action items: klotz leigh

WARNING: Input appears to use implicit continuation lines.
You may need the "-implicitContinuations" option.


[End of scribe.perl diagnostic output]