IRC log of waf on 2008-02-06
Timestamps are in UTC.
- 19:57:54 [RRSAgent]
- RRSAgent has joined #waf
- 19:57:54 [RRSAgent]
- logging to http://www.w3.org/2008/02/06-waf-irc
- 19:57:56 [trackbot-ng]
- RRSAgent, make logs member
- 19:57:56 [Zakim]
- Zakim has joined #waf
- 19:57:58 [trackbot-ng]
- Zakim, this will be WAF
- 19:57:58 [Zakim]
- ok, trackbot-ng; I see IA_WAF()3:00PM scheduled to start in 3 minutes
- 19:57:59 [trackbot-ng]
- Meeting: Web Application Formats Working Group Teleconference
- 19:57:59 [trackbot-ng]
- Date: 06 February 2008
- 19:58:11 [ArtB]
- Agenda: http://lists.w3.org/Archives/Public/public-appformats/2008Feb/0027.html
- 19:58:13 [MikeSmith]
- zakim, code?
- 19:58:13 [Zakim]
- the conference code is 9231 (tel:+1.617.761.6200 tel:+33.4.89.06.34.99 tel:+44.117.370.6152), MikeSmith
- 19:58:39 [Zakim]
- IA_WAF()3:00PM has now started
- 19:58:46 [Zakim]
- +??P3
- 19:58:51 [ArtB]
- rrsagent, make logs public
- 19:58:53 [anne]
- Zakim. who is om the phone?
- 19:58:58 [MikeSmith]
- Zakim, ??P3 is me
- 19:58:58 [Zakim]
- +MikeSmith; got it
- 19:59:06 [anne]
- Zakim. who is on the phone?
- 19:59:18 [Zakim]
- +MSEder
- 19:59:29 [ArtB]
- zakim, MSEder is ArtB
- 19:59:29 [Zakim]
- +ArtB; got it
- 20:00:10 [anne]
- Zakim, who is on the phone?
- 20:00:10 [Zakim]
- On the phone I see MikeSmith, ArtB
- 20:03:37 [Zakim]
- +Dave_Orchard
- 20:04:39 [dorchard]
- dorchard has joined #waf
- 20:04:48 [dorchard]
- zakim, who's on the phone?
- 20:04:48 [Zakim]
- On the phone I see MikeSmith, ArtB, Dave_Orchard
- 20:05:18 [anne]
- ArtB, k
- 20:05:25 [Zakim]
- +[Mozilla]
- 20:05:48 [sicking]
- sicking has joined #waf
- 20:06:01 [ArtB]
- zakim, Mozilla is Sicking
- 20:06:01 [Zakim]
- +Sicking; got it
- 20:06:17 [anne]
- Zakim, passcode?
- 20:06:17 [Zakim]
- the conference code is 9231 (tel:+1.617.761.6200 tel:+33.4.89.06.34.99 tel:+44.117.370.6152), anne
- 20:06:23 [ArtB]
- Scribe: Art
- 20:06:29 [ArtB]
- ScribeNick: ArtB
- 20:06:32 [ArtB]
- Chair: Art
- 20:06:45 [Zakim]
- +anne
- 20:06:54 [ArtB]
- Present: Art, Jonas, David, Mike, Anne, Thomas (IRC)
- 20:07:01 [ArtB]
- Topic: Review Agenda
- 20:07:46 [ArtB]
- AB: we will skip #2 and #3 since there were no comments on those agenda items
- 20:08:09 [ArtB]
- Topic: Proposal for a way to avoid round-trip ...
- 20:08:36 [ArtB]
- AB: Anne, what's the status?
- 20:08:42 [ArtB]
- AvK: pending some comments
- 20:08:51 [ArtB]
- ... integrated in the ED now
- 20:09:13 [ArtB]
- AB: who are you waiting for comments from?
- 20:09:24 [ArtB]
- AvK: everyone i.e. no one in particular
- 20:09:31 [ArtB]
- ... Jonas had some comments
- 20:09:45 [ArtB]
- JS: not much we can do to tweak this
- 20:10:06 [ArtB]
- ... not sure we can do what Mark wants
- 20:10:31 [ArtB]
- JS: I think the current spec is as secure as it can be made
- 20:10:47 [ArtB]
- AvK: Google says its important as well as the REST guys
- 20:11:19 [ArtB]
- AB: does this proposal address the issues the REST guys made
- 20:11:24 [ArtB]
- AvK: yes, I think so
- 20:11:31 [ArtB]
- JS: but they haven't responded as such
- 20:11:48 [ArtB]
- DO: I found it hard to follow; not sure how it all works together
- 20:12:01 [ArtB]
- ... may be waiting for it to be integrated in the spec
- 20:12:10 [ArtB]
- AvK: I've also added examples to the spec
- 20:12:30 [ArtB]
- ... I think I've addressed their concerns
- 20:12:51 [ArtB]
- ... If 10 posts, need to do 12 requests total and that's not too bad
- 20:13:03 [ArtB]
- JS: would still like to get some more feedback from them
- 20:13:13 [ArtB]
- AvK: I agree explicit consent would be better
- 20:13:33 [ArtB]
- JS: there a couple of minor details I still want to change but they aren't behavioral
- 20:13:42 [ArtB]
- ... e.g. some stuff with the slashes
- 20:13:56 [ArtB]
- AvK: must start with a slash but doesn't have to end with one
- 20:14:30 [ArtB]
- JS: if I have the foo dir is /foo or /foo/?
- 20:14:39 [ArtB]
- ... not clear where to put the policy
- 20:15:29 [ArtB]
- JS: it would be good to get some more feedback on the URI syntax
- 20:15:41 [ArtB]
- AvK: agree but that would be relatively easy to change
- 20:17:00 [ArtB]
- AB: agree we need more review and "explicit consent"; how do we get that?
- 20:17:09 [ArtB]
- DO: typically would publish a new WD
- 20:17:42 [ArtB]
- AvK: could you send an email to Mark, Tyler, and others?
- 20:17:52 [ArtB]
- DO: Stuart and I also raised related concerns
- 20:17:57 [MikeSmith]
- Tyler is Tyler Close
- 20:18:09 [ArtB]
- AvK: would like to get quick feedback
- 20:18:34 [ArtB]
- DO: the reqs seem to be settling but this is a big change thus a new WD seems like the right way to go
- 20:18:50 [ArtB]
- AvK: I suppose a new WD would be OK but prefer a LC
- 20:19:02 [ArtB]
- ... we could publish a WD and then in a few weeks go to LC
- 20:19:34 [ArtB]
- DO: I think the changes are too substantial to go directly to LC
- 20:19:52 [ArtB]
- AvK: there is a precedence to publish a FPWD and LC at the same time
- 20:20:05 [ArtB]
- AB: any objections to an immediate new WD?
- 20:20:22 [ArtB]
- AvK: don't want it to delay LC
- 20:20:42 [tlr]
- zakim, call thomas-skype
- 20:20:42 [Zakim]
- ok, tlr; the call is being made
- 20:20:44 [Zakim]
- +Thomas
- 20:21:04 [ArtB]
- AB: Mike, what is the Team's position?
- 20:21:16 [ArtB]
- ... on WD and LC?
- 20:22:32 [ArtB]
- MS: I think there have been too many objections to this work item to publish this as an LC under the current charter and its extension
- 20:22:51 [ArtB]
- ... this isn't a final decision by the Team but that's where we stand now
- 20:23:22 [ArtB]
- AvK: are these objections from the Team or Members? Where is the archive?
- 20:23:44 [ArtB]
- MS: some on the public archive; some based on internal discussions
- 20:24:03 [ArtB]
- AvK: I think we've addressed the issues raised
- 20:24:27 [ArtB]
- MS: there is a question about whether this spec is within the group's charter
- 20:25:15 [ArtB]
- ... The charter is a bit broad
- 20:25:35 [ArtB]
- ... I think the group did this work in good faith
- 20:25:49 [ArtB]
- ... If people didn't pay attention, that's not this group's fault
- 20:26:12 [ArtB]
- ... I don't think anyone tried to "sneak in this work"
- 20:27:20 [dorchard]
- I'm not sure what this means for the group publishing another Working Draft though...
- 20:27:37 [ArtB]
- TR: I don't have much to add to what Mike said
- 20:28:06 [ArtB]
- ... There should not be a LC going out under the current charter
- 20:28:35 [ArtB]
- MS: that is true i.e. that's the Team's consensus
- 20:29:33 [ArtB]
- AvK: the Selectors spec in the Web API WG was able to go to LC
- 20:29:52 [ArtB]
- ... despite going out of charter
- 20:30:01 [ArtB]
- TR: I don't know the specifics of that case
- 20:30:33 [ArtB]
- JS: one reason this group started this work is because this mechanism is needed by XBL2
- 20:31:21 [ArtB]
- AB: I agree and have argued that point
- 20:31:38 [ArtB]
- ... Seems like the problem is that we are now in this "limbo" state
- 20:31:46 [anne]
- http://www.w3.org/TR/selectors-api/ is the precedent I was talking about
- 20:32:15 [ArtB]
- MS: not clear how long it will take for the new charter to get approved
- 20:33:10 [ArtB]
- ... we have a combination of the "limbo" state but also not clear where this is going to end up in the next charters
- 20:33:24 [ArtB]
- DO: we should be able to publish a new WD, right?
- 20:33:31 [ArtB]
- ... or is that not allowed?
- 20:34:27 [ArtB]
- AB: yes, what is the answer Mike?
- 20:34:43 [ArtB]
- MS: I can't make a decision now
- 20:34:44 [tlr]
- q+
- 20:34:56 [ArtB]
- AvK: when will you know?
- 20:35:36 [ArtB]
- TR: based on my recollection - there will be no LC pub; I do not recall a decsion on the WD question
- 20:36:04 [ArtB]
- ... If the WG wants to publish a "normal" WD then the Team can discuss this
- 20:36:17 [ArtB]
- AvK: we want not just a new WD but also a LC
- 20:36:18 [dorchard]
- q+
- 20:36:21 [tlr]
- q-
- 20:36:59 [MikeSmith]
- q+ to say I can go ahead with plan to publish a WD first
- 20:37:00 [ArtB]
- DO: I think we should publish a WD and not a LC regardless of precedence
- 20:37:19 [ArtB]
- AvK: again, I'm OK with a WD now but then want a LC two weeks later
- 20:38:40 [ArtB]
- AB: perhaps we can consensus to publish a WD now and then ask the Team to consider us publishing a LC during the extension period
- 20:39:22 [ArtB]
- AvK: I think there is indeed a precedence for us to publish a LC during the extension period
- 20:40:04 [ArtB]
- AB: I propose we publish a new WD ASAP
- 20:40:09 [ArtB]
- AB: any objections?
- 20:40:26 [ArtB]
- [none heard]
- 20:40:35 [ArtB]
- AB: any changes you want to make Anne?
- 20:40:43 [ArtB]
- AvK: just a few changes
- 20:40:56 [ArtB]
- DO: and I have a couple of quick changes I'd like to get in
- 20:42:11 [ArtB]
- MS: once we are ready, we should be able to get it published quickly
- 20:42:39 [ArtB]
- RESOLUTION: publish a new WD as soon as Anne is ready
- 20:42:48 [ArtB]
- DO: let's set a deadline for comments
- 20:43:00 [ArtB]
- AB: OK
- 20:43:14 [ArtB]
- AvK: let's set the target for next Tuesday
- 20:43:47 [ArtB]
- ACTION: Mike determine the Team's position on us publishing a LC version during this extension period
- 20:43:47 [trackbot-ng]
- Sorry, amibiguous username (more than one match) - Mike
- 20:43:47 [trackbot-ng]
- Try using a different identifier, such as family name or username (eg. mamend, mike)
- 20:44:30 [MikeSmith]
- ACTION: Michael(tm) to determine the Team's position on us publishing a LC version during this extension perioad
- 20:44:30 [trackbot-ng]
- Created ACTION-167 - Determine the Team's position on us publishing a LC version during this extension perioad [on Michael(tm) Smith - due 2008-02-13].
- 20:44:32 [tlr]
- I have no such sense.
- 20:44:52 [ArtB]
- AB: Mike, when do you expect the charter to go out for formal AC review?
- 20:45:14 [tlr]
- s/no such sense/no good sense when charter review will happen/
- 20:45:46 [ArtB]
- MS: I will push this and hope to get it out next week
- 20:46:02 [ArtB]
- AB: ok, great
- 20:46:43 [tlr]
- MS: I will report back to the group when I have a clearer idea; can't do that today, though
- 20:47:25 [MikeSmith]
- tlr - thanks
- 20:48:04 [Zakim]
- -Thomas
- 20:49:32 [MikeSmith]
- q?
- 20:49:38 [MikeSmith]
- q-
- 20:49:54 [ArtB]
- Topic: Issue #21
- 20:51:01 [ArtB]
- AB: are there any gaps or holes that need to be filled?
- 20:51:15 [ArtB]
- ... the latest ED contains a lot of info to address this issue
- 20:51:59 [ArtB]
- JS: we used to have a description about what can currently be done regarding XSS but it was removed
- 20:52:19 [ArtB]
- ... would like to know why it was removed because it seems like that info is relevant for the Security Model
- 20:52:53 [ArtB]
- AvK: I think we just changed the Intro; it's bit more abstract now
- 20:53:03 [ArtB]
- ... we still mention the Same Origin Policy
- 20:53:31 [ArtB]
- AB: Jonas, can you identify the text you'd like to get added?
- 20:53:40 [ArtB]
- JS: yes, I can submit something
- 20:56:10 [ArtB]
- ACTION: Jonas submit an input that will result in closing Issue #21
- 20:56:10 [trackbot-ng]
- Created ACTION-168 - Submit an input that will result in closing Issue #21 [on Jonas Sicking - due 2008-02-13].
- 20:56:52 [MikeSmith]
- action-155?
- 20:56:52 [trackbot-ng]
- ACTION-155 -- Jonas Sicking to send a request for comments regarding the policy decision questions and issues -- due 2008-01-30 -- CLOSED
- 20:56:52 [trackbot-ng]
- http://www.w3.org/2005/06/tracker/waf/actions/155
- 20:57:15 [MikeSmith]
- issue-21?
- 20:57:15 [trackbot-ng]
- ISSUE-21 -- What is the Security Model for the access-control spec? -- RAISED
- 20:57:15 [trackbot-ng]
- http://www.w3.org/2005/06/tracker/waf/issues/21
- 20:57:40 [ArtB]
- Topic: Issue #20
- 20:58:42 [ArtB]
- AB: have a detailed discussion on the mail list
- 20:59:53 [ArtB]
- ... we've had inputs from Thomas, Tyler, Jonas and maybe others
- 20:59:58 [ArtB]
- ... Jonas: http://lists.w3.org/Archives/Public/public-appformats/2008Feb/0007.html
- 21:00:30 [ArtB]
- ... just want to discuss how to get consensus and keep the technical discussion on the mail list
- 21:01:00 [ArtB]
- JS: need to have some policy enforcement in the client
- 21:01:17 [ArtB]
- AvK: I want to close
- 21:01:32 [ArtB]
- DO: I'm still concerned about this issue
- 21:01:48 [ArtB]
- ... we've been discussing this issue internally
- 21:01:56 [ArtB]
- ... I'm not prepared to close it now
- 21:02:03 [ArtB]
- JS: but we need feedback on this issue
- 21:02:21 [ArtB]
- DO: I understand; it's been hard to get the right people in BEA involved
- 21:02:37 [ArtB]
- ... I've been talking to other people too; I'm active on it
- 21:03:03 [ArtB]
- JS: currently client PEP adds complexity
- 21:03:17 [ArtB]
- ... wonder if we have added to many features
- 21:03:24 [Zakim]
- -MikeSmith
- 21:03:31 [ArtB]
- ... but I'll post my comments on the mail list
- 21:03:44 [dorchard]
- dorchard has joined #waf
- 21:06:23 [billyjack]
- billyjack has joined #waf
- 21:06:33 [ArtB]
- [ some discussion missing ... ]
- 21:07:03 [billyjack]
- Zakim, code?
- 21:07:03 [Zakim]
- the conference code is 9231 (tel:+1.617.761.6200 tel:+33.4.89.06.34.99 tel:+44.117.370.6152), billyjack
- 21:07:26 [anne]
- sicking:
- 21:07:27 [ArtB]
- Topic: Issue #22 ac4csr-webarch
- 21:07:39 [Zakim]
- +[IPcaller]
- 21:07:50 [anne]
- sicking, so dropping method whitelisting?
- 21:07:53 [billyjack]
- Zakim, IPcaller is me
- 21:07:53 [Zakim]
- +billyjack; got it
- 21:08:01 [sicking]
- anne, yes
- 21:08:46 [ArtB]
- AB: what should we do with this?
- 21:08:47 [anne]
- seems fine to me... less text :)
- 21:08:58 [ArtB]
- DO: I thought the Hixie and Anne proposal addressed it
- 21:09:03 [ArtB]
- AvK: yes I agree
- 21:09:15 [ArtB]
- DO: I think we should resolve it as closed
- 21:09:38 [ArtB]
- ACTION: Orchard close issue #22
- 21:09:38 [trackbot-ng]
- Created ACTION-169 - Close issue #22 [on David Orchard - due 2008-02-13].
- 21:09:58 [ArtB]
- Topic: AOB
- 21:10:20 [ArtB]
- AB: do we want to have a call next week?
- 21:10:26 [ArtB]
- AvK: I'm fine either way
- 21:10:43 [ArtB]
- DO: hopefully we should have just published a WD and may not have much to talk about
- 21:10:50 [ArtB]
- AB: I tend to agree
- 21:10:55 [ArtB]
- AvK: what about two week?
- 21:11:21 [ArtB]
- AB: sounds good and hopefull Mike will have an answer from tthe Team regarding LC by then
- 21:11:44 [ArtB]
- JS: Mozilla is going to do a security review next Tuesday
- 21:11:57 [ArtB]
- ... it is open to the public and anyone can dial in
- 21:12:04 [ArtB]
- ... I will post details to the mail list
- 21:12:18 [ArtB]
- AB: listen mode only OK?
- 21:12:22 [ArtB]
- JS: absolutely
- 21:13:00 [ArtB]
- MS: yes, two weeks should be enough time
- 21:13:14 [ArtB]
- AB: no call next week; next call on Feb 20
- 21:13:32 [Zakim]
- -Dave_Orchard
- 21:13:41 [ArtB]
- AB: meeting adjourned
- 21:13:41 [Zakim]
- -anne
- 21:13:43 [Zakim]
- -billyjack
- 21:13:45 [Zakim]
- -Sicking
- 21:13:46 [Zakim]
- -ArtB
- 21:13:46 [Zakim]
- IA_WAF()3:00PM has ended
- 21:13:47 [Zakim]
- Attendees were MikeSmith, ArtB, Dave_Orchard, Sicking, anne, Thomas, billyjack
- 21:13:55 [ArtB]
- rrsagent, make minutes
- 21:13:55 [RRSAgent]
- I have made the request to generate http://www.w3.org/2008/02/06-waf-minutes.html ArtB
- 21:14:34 [ArtB]
- Present: Art, Anne, Mike, Jonas, David, Thomas
- 21:14:41 [ArtB]
- rrsagent, make minutes
- 21:14:41 [RRSAgent]
- I have made the request to generate http://www.w3.org/2008/02/06-waf-minutes.html ArtB
- 21:15:02 [ArtB]
- zakim, bye
- 21:15:02 [Zakim]
- Zakim has left #waf
- 21:19:58 [ArtB]
- rrsagent, bye
- 21:19:58 [RRSAgent]
- I see 4 open action items saved in http://www.w3.org/2008/02/06-waf-actions.rdf :
- 21:19:58 [RRSAgent]
- ACTION: Mike determine the Team's position on us publishing a LC version during this extension period [1]
- 21:19:58 [RRSAgent]
- recorded in http://www.w3.org/2008/02/06-waf-irc#T20-43-47
- 21:19:58 [RRSAgent]
- ACTION: Michael(tm) to determine the Team's position on us publishing a LC version during this extension perioad [2]
- 21:19:58 [RRSAgent]
- recorded in http://www.w3.org/2008/02/06-waf-irc#T20-44-30
- 21:19:58 [RRSAgent]
- ACTION: Jonas submit an input that will result in closing Issue #21 [3]
- 21:19:58 [RRSAgent]
- recorded in http://www.w3.org/2008/02/06-waf-irc#T20-56-10
- 21:19:58 [RRSAgent]
- ACTION: Orchard close issue #22 [4]
- 21:19:58 [RRSAgent]
- recorded in http://www.w3.org/2008/02/06-waf-irc#T21-09-38