13:43:02 RRSAgent has joined #dap 13:43:02 logging to http://www.w3.org/2010/10/20-dap-irc 13:43:04 RRSAgent, make logs world 13:43:04 Zakim has joined #dap 13:43:06 Zakim, this will be DAP 13:43:06 ok, trackbot; I see UW_DAP()10:00AM scheduled to start in 17 minutes 13:43:07 Meeting: Device APIs and Policy Working Group Teleconference 13:43:07 Date: 20 October 2010 13:43:40 Agenda: http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0043.html 13:44:25 Regrets+ Suresh_Chitturi 13:44:39 Chair: Robin_Berjon, Frederick_Hirsch 13:44:42 Present Cecile_Marc 13:44:55 Present+ Robin_Berjon, Frederick_Hirsch 13:45:32 Present+ Cecile_Marc 13:45:49 Regrets+ Marco _Marengo 13:45:57 s/Present Cecile_Marc// 13:49:21 Regrets+ Wonsuk_Lee 13:49:27 UW_DAP()10:00AM has now started 13:49:35 + +33.2.99.12.aaaa 13:50:14 Regrets+ Mohammed_Dadas 13:54:43 - +33.2.99.12.aaaa 13:54:44 UW_DAP()10:00AM has ended 13:54:44 Attendees were +33.2.99.12.aaaa 13:55:12 zakim, who is here? 13:55:12 apparently UW_DAP()10:00AM has ended, fjh 13:55:14 On IRC I see RRSAgent, Marcos, cmarc, richt, tlr, fjh, arve, wmaslowski, shepazu, ilkka, ingmar, trackbot, dom 13:55:23 arve has left #dap 13:55:28 this is a test 13:55:35 fjh, we all didn't see it 13:55:43 rrsagent, generate minutes 13:55:43 I have made the request to generate http://www.w3.org/2010/10/20-dap-minutes.html fjh 13:56:31 s/this is a test// 13:56:50 s/fjh, we all didn't see it// 13:57:28 UW_DAP()10:00AM has now started 13:57:35 +??P8 13:57:39 zakim, ??P8 is me 13:57:39 +fjh; got it 13:57:44 rrsagent, generate minutes 13:57:44 I have made the request to generate http://www.w3.org/2010/10/20-dap-minutes.html fjh 13:57:58 richt has joined #dap 13:59:29 + +33.2.99.12.aaaa 13:59:57 darobin has joined #dap 14:00:26 jmorris has joined #dap 14:00:26 +??P15 14:00:26 zakim, aaaa is cmarc 14:00:27 +cmarc; got it 14:00:35 zakim, who is here? 14:00:40 On the phone I see fjh, cmarc, ??P15 14:00:50 On IRC I see jmorris, darobin, richt, Zakim, RRSAgent, Marcos, cmarc, tlr, fjh, wmaslowski, shepazu, ilkka, ingmar, trackbot, dom 14:00:56 zakim, ??P15 is me 14:01:01 Claes has joined #dap 14:01:01 +darobin; got it 14:01:15 +Dom 14:01:23 Present+ Dominique_Hazael-Massieux 14:01:34 nwidell has joined #dap 14:01:39 +jmorris 14:01:41 Zakim, who's noisy? 14:01:43 LauraA has joined #dap 14:01:58 Present+ LauraA 14:02:14 dom, listening for 10 seconds I heard sound from the following: darobin (33%), jmorris (34%) 14:02:16 Dzung_Tran has joined #dap 14:02:21 Present+ Dzung_Tran 14:02:22 +Claes 14:02:30 Present+ John_Morris 14:02:35 +nwidell 14:02:43 Present+ Niklas_Widell 14:02:46 +ilkka 14:02:57 Present+ Ilkka_oksanen 14:03:01 Present+ Claes_Nilsson 14:04:14 zakim, call thomas-781 14:04:14 ok, tlr; the call is being made 14:04:16 +Thomas 14:04:20 zakim, I am thomas 14:04:20 ok, tlr, I now associate you with Thomas 14:04:22 zakim, mute me 14:04:22 Thomas should now be muted 14:04:29 zakim, who is here? 14:04:29 On the phone I see fjh, cmarc, darobin, Dom, jmorris, Claes, nwidell, ilkka, Thomas (muted) 14:04:31 On IRC I see Dzung_Tran, LauraA, nwidell, Claes, jmorris, darobin, richt, Zakim, RRSAgent, Marcos, cmarc, tlr, fjh, wmaslowski, shepazu, ilkka, ingmar, trackbot, dom 14:04:45 +richt 14:05:18 ScribeNick: jmorris 14:05:27 Topic: Administrative 14:05:33 +LauraA 14:05:47 fjh: talk about f2f 14:05:55 zakim, who is here? 14:05:55 On the phone I see fjh, cmarc, darobin, Dom, jmorris, Claes, nwidell, ilkka, Thomas (muted), richt, LauraA 14:05:57 On IRC I see Dzung_Tran, LauraA, nwidell, Claes, jmorris, darobin, richt, Zakim, RRSAgent, Marcos, cmarc, tlr, fjh, wmaslowski, shepazu, ilkka, ingmar, trackbot, dom 14:06:03 AnssiK has joined #dap 14:06:10 ... will send f2f agenda soon 14:06:16 Present+ Anssi_Kostiainen 14:06:24 enewland has joined #dap 14:06:47 ... any suggestions for agenda would be welcome 14:06:48 Marcos_ has joined #dap 14:06:59 present+ erica+newland 14:06:59 Present+ Richard_Tibbett 14:07:04 present+ erica_newland 14:07:10 +AnssiK 14:07:30 maoteo has joined #dap 14:07:36 ... possibly we should talk with Web Notifications about permissions stuff 14:07:41 (it doesn't look like they will meet there) 14:07:54 Present+ Maria_Oteo 14:08:01 http://www.w3.org/2010/11/TPAC/#GroupSchedule 14:08:08 lgombos has joined #dap 14:08:09 (yeah, I'd be surprised if they ever met, given the group) 14:08:20 Zakim, jmorris holds enewland 14:08:20 +enewland; got it 14:09:37 + +34.97.421.aabb 14:09:54 ... what is going on with Geolocation 14:10:00 Zakim, aabb is maoteo 14:10:00 +maoteo; got it 14:10:14 Claes: I am working with Geolocation 14:10:34 ... they are not working specifically on security/privacy right now 14:10:54 Zakim, mute me 14:10:56 Dom should now be muted 14:11:18 ... perhaps discussion on geoloc privacy, but not directly related to DAP 14:11:43 fjh: we are overlapping with HTML WG, perhaps we should talk with them 14:11:44 ack me 14:11:47 danielcoloma has joined #dap 14:12:05 Zakim, mute me 14:12:05 Dom should now be muted 14:12:26 Present+ Daniel_Coloma 14:12:30 darobin: I can contact Web Notification, and we should also talk to html 14:12:45 Zakim, maoteo holds danielcoloma 14:12:45 +danielcoloma; got it 14:12:46 ACTION: Robin to ping HTML chairs, Notifications chair to see about potential joint meetings 14:12:46 Created ACTION-284 - Ping HTML chairs, Notifications chair to see about potential joint meetings [on Robin Berjon - due 2010-10-27]. 14:12:54 fjh: darobin to contact HTML, fjh to contact Web Notification 14:13:19 ACTION: fjh to ping web notification group 14:13:19 Created ACTION-285 - Ping web notification group [on Frederick Hirsch - due 2010-10-27]. 14:14:34 q+ 14:14:36 q+ 14:14:44 ack anssiK 14:15:00 darobin: possibly talk at f2f about test suites 14:15:09 q? 14:15:21 +1 on reusing PhoneGap's stuff if possible 14:15:25 +1 too 14:15:27 AnssiK: can re reuse test suite phonecap 14:15:38 anssi: asks about reusing phone gap test suite 14:15:48 s/phonecap/phonegap/ 14:15:54 s/phone gap/phonegap/ 14:15:54 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0031.html 14:15:58 q+ to talk on licenses 14:16:09 ack me 14:16:10 dom, you wanted to talk on licenses 14:16:27 http://www.w3.org/Consortium/Legal/2008/04-testsuite-license.html 14:16:34 dom: w3c has special license for document and PST? license 14:16:55 ... so we can probably reuse the PhoneGap test suite either because 14:17:05 ... license covers it or we can ask if needed 14:17:11 http://www.w3.org/Consortium/Legal/2008/04-testsuite-copyright.html 14:17:42 jmorris: should we put an action on dom to check on license 14:17:55 ack richt 14:17:57 Proposed test suite methodology for e.g. Contacts: http://www.w3.org/TR/test-methodology/ 14:18:02 action: dom to check licensing issues on phonegap test suite 14:18:02 Created ACTION-286 - Check licensing issues on phonegap test suite [on Dominique Hazaël-Massieux - due 2010-10-27]. 14:18:21 (I wonder if Anssi would be interested in presenting/demoing the phonegap tests) 14:18:26 richt: discussing contacts test suite 14:18:28 ok, it looks like we need some time at F2F to work through test suite topics 14:18:43 +1 to AnssiK demoing the PG tests 14:19:02 (I could probably make a quick intro to testing @w3c, and the test methodology) 14:19:09 +1 to that 14:19:16 fjh: could Anssi demo PhoneGap test suite 14:19:31 +1 to dom introducing testing at w3 and ansii sharing understanding of PhoneGap test suite 14:19:40 AnssiK: I am not a PhoneGap guy, but I will look at it 14:19:40 ACTION: Anssi to introduce phonegap tests during F2F 14:19:40 Created ACTION-287 - Introduce phonegap tests during F2F [on Anssi Kostiainen - due 2010-10-27]. 14:19:55 ACTION: Dom to introduce testing@w3c during F2F 14:19:55 Created ACTION-288 - Introduce testing@w3c during F2F [on Dominique Hazaël-Massieux - due 2010-10-27]. 14:20:01 agree with fjh, Dom to introduce testing at W3C and demo of PG tests. 14:20:09 ...at the F2F 14:20:20 q+ on agenda 14:20:40 darobin: should we do a wiki page for the agenda? 14:20:49 ACTION: Robin to create Wiki page for f2f agenda 14:20:49 Created ACTION-289 - Create Wiki page for f2f agenda [on Robin Berjon - due 2010-10-27]. 14:21:24 q? 14:21:36 ack dom 14:21:36 dom, you wanted to comment on agenda 14:21:42 dom: at f2f, we should spend time on roadmap 14:21:50 dom suggests review of RoadMap 14:21:54 ... we should have a written roadmap by end of year 14:22:44 TPAC registration (for in-person attendees) http://www.w3.org/2002/09/wbs/35125/TPAC2010reg/ 14:22:48 fjh: our home page is our roadmap, do we need another docuemnt? 14:22:52 TPAC registration fee increases on 22 October 14:23:04 s/cuem/cume/ 14:23:11 DST difference to consider if dialing in to TPAC - http://lists.w3.org/Archives/Member/member-device-apis/2010Oct/0002.html 14:23:15 (we have 32 registered participants for the F2F, not too bad) 14:23:23 -> http://www.w3.org/2009/dap/wiki/TPAC10Agenda TPAC 10 agenda scratchpad 14:23:26 fjh: registration for TPAC closes soon 14:23:36 File API updates 14:23:45 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0027.html 14:23:48 ... if you are dialing in you must be careful about timezones, daylight savings, etc. 14:23:59 ... update of file permissions spec 14:24:24 topic: Minutes approval 14:24:35 Approve 6 October minutes 14:24:35 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/att-0014/minutes-2010-10-06.html 14:24:38  14:24:43 proposed RESOLUTION: Minutes from 6 October 2010 approved 14:25:00 RESOLUTION: Minutes from 6 October 2010 approved 14:25:08 topic: Permissions spec 14:25:17 I'm here 14:25:17 parameterization, http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0034.html 14:25:25 q+ 14:25:33 fjh: nicholas sent a message re granuality 14:26:05 (the permissions may need to be parametrized per recipient/sender) 14:26:24 who?: problem is not what you mentioned 14:26:40 s/who?/niklas/ 14:26:42 ... problem is that widget will be notified for every message on system 14:26:52 ack nwidell 14:26:57 s/nicholas/niklas/ 14:27:16 q+ 14:27:32 ... need to be clear on what kinds of messages the widget can see 14:27:40 ack dom 14:28:14 dom: one way would be to paramaterize the permissions, or have the API be minimized so you can only use it for a well defined set or recipients 14:28:40 issue is limiting permission on api to only allow messages to/from given address etc. also separate different types of messaging 14:28:49 ... messaging API should give access only to well defined set of recipients 14:29:00 q+ 14:29:03 q+ to ask about use case 14:29:05 q+ 14:29:12 ack nwidell 14:29:22 ACTION-132? 14:29:22 ACTION-132 -- Max Froumentin to look at messaging subscribe with filtering and events -- due 2010-03-25 -- OPEN 14:29:22 http://www.w3.org/2009/dap/track/actions/132 14:29:34 see also http://lists.w3.org/Archives/Public/public-device-apis/2010Mar/att-0180/minutes-2010-03-18.html#item01 14:30:00 nwidell: want to have permission up front 14:30:06 ... when get it otherwise? 14:30:20 fjh: how would I assign permissions 14:30:39 ... I might want to receive from someone I did not anticipate 14:30:50 dom: it is about the application, not the user 14:31:08 ... I agree that we need to decide on defining up front or not 14:31:26 ... we need use cases for messaging where we can define a proper security model 14:31:34 +1 to knowing what it is we want to do with messaging in the first place 14:31:45 q+ 14:31:51 ack fjh 14:31:51 fjh, you wanted to ask about use case 14:31:54 ack AnssiK 14:32:15 Mozilla released their Open Web Apps platform I think yesterday, they'reeyeing at "Permissions for Device API Access" spec and might have good feedback based on impl experiences: https://apps.mozillalabs.com/web_or_native.html 14:32:34 AnssiK: openwebapps platform is attacking similar problems 14:32:50 ... they are stating that they are looking into permissions for device API 14:32:59 ... who would be a good mozilla contact 14:33:21 ... we should get feedback from people implementing stuff 14:33:41 (I hadn't seen the ref to the permissions draft in https://apps.mozillalabs.com/web_or_native.html - cool!) 14:33:48 ... hans? from mozilla seems to be working on plug ins 14:33:59 ... those guys seem to be following what we are doing 14:34:08 s/hans?/hanson/ 14:34:15 ... I do not know the mozilla people personally 14:34:16 Mark Hanson 14:34:32 s/Mark/Mike/ 14:34:37 action: contact mozilla for thoughts on messaging and permission spec 14:34:37 Sorry, couldn't find user - contact 14:34:52 action: fjh contact mozilla for thoughts on messaging and permission spec 14:34:52 Created ACTION-290 - Contact mozilla for thoughts on messaging and permission spec [on Frederick Hirsch - due 2010-10-27]. 14:35:01 q? 14:35:05 ack nwidell 14:35:39 (not sure we need to contacts Mozilla on messaging; permissions sounds enough) 14:35:53 (agreed) 14:36:28 dom: asking re who is working on permission spec 14:36:38 ACTION: Maria to work on security model for messaging 14:36:38 Created ACTION-291 - Work on security model for messaging [on Maria Angeles Oteo - due 2010-10-27]. 14:36:43 (the Moz Open Web Apps experiment at GitHub: http://github.com/mozilla/openwebapps) 14:36:56 s/permission/messaging/ 14:36:59 Topic: Privacy 14:37:00 zakim, mute me 14:37:00 Dom should now be muted 14:37:13 ACTION-210? 14:37:13 ACTION-210 -- Alissa Cooper to summarize and add issues to ruleset doc -- due 2010-07-21 -- OPEN 14:37:13 http://www.w3.org/2009/dap/track/actions/210 14:37:25 fjh: Alissa added issues to ruleset document 14:37:55 q+ 14:38:02 ack me 14:38:14 darobin: do we discuss publishing at f2f 14:38:32 dom: we want to have idea of how to address issues raised at f2f 14:39:31 dom: some of the issues are fundamental 14:39:49 ... before issuing document we need to understand that some issues are not addressable 14:39:54 ... we need to 14:40:14 get an idea of what issues we would not be able to address 14:40:46 dom: starting a FPWD suggests we know what we are doing 14:40:47 ... 14:40:48  14:40:49  14:40:51 ... 14:41:28 fjh: look at issues on list 14:41:32 ... before the f2f 14:41:45 action: fjh to review ruleset issues 14:41:45 Created ACTION-292 - Review ruleset issues [on Frederick Hirsch - due 2010-10-27]. 14:41:50 -AnssiK 14:42:10 Topic: Contacts 14:42:13 AnssiK1 has joined #dap 14:42:29 fjh: clickjacking 14:42:43 +AnssiK 14:42:48 Clickjacking threat and countermeasures 14:42:48 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0017.html 14:42:55 darobin: it is not clear that clickjacking is something we need to solve at API level 14:43:01 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0018.html 14:43:25 ... or something that needs to be solved more generally 14:43:26 -> http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0025.html CSP 14:43:43 ... this might provide a path toward solution 14:43:56 ... but I'm not a security expert 14:44:08 +1 agree with Robin but not too sure on the CSP connection :/ 14:44:35 dom: CSP may help solve some of problem but cannot 14:44:44 q+ 14:44:46 dom: CSP is server side, so not enough for client-side API 14:44:55 ... use is as a security argument in API 14:45:06 ack AnssiK1 14:45:12 darobin: soluitons will come from broader options 14:45:32 +1 to not doing anything new 14:45:34 AnssiK: we should not do anything that has not been done before 14:45:52 ... let's not open can of worms 14:46:17 ... so let's use, for example, fileinput, rather than obscure way for user input 14:46:39 ... if we use general mechanisms that have been tested, we are safer 14:47:15 darobin: agree not to invent new input methods 14:47:53 richt: looked only briefly at it 14:48:05 ... idea is to go straight to trusted events 14:48:21 ... talks about synthesized events and how they can be mitigated 14:48:37 Zakim, mute me 14:48:37 Dom should now be muted 14:48:42 ... but I still need to put some language into the contact spec 14:50:11 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0021.html 14:50:30 https://developer.mozilla.org/en/Using_files_from_web_applications#Using_hidden_file_input_elements_using_the_click%28%29_method 14:50:35 AnssiK: robin's e-mail raises issue - Anssi could not find it in spec 14:51:15 darobin: look at link 14:51:38 ... if they make this possible, it may suggest that the security issue has been solved 14:51:47 that's is an important point Robin. Thanks for the link. 14:52:17 richt?: this is helpful input 14:52:30 s/richt?/richt/ 14:52:34 ... this reenforces our approach to this 14:53:04 darobin: this helps decide the issue 14:53:25 richt: a synthesized event is possible 14:53:46 ... I will put some of this into document by TPAC 14:54:11 darobin: now to phonegap implemention 14:54:33 ... good that they have implemented, but not sure we need to discuss more now 14:54:48 richt: good we have phonegap reenforcing what we are doing 14:54:58 q+ 14:55:04 ... good that UI is nonnormative 14:55:14 ack AnssiK1 14:55:16 topics 14:55:24 s/topics// 14:56:00 AnssiK: android is having hard time including all elements ? 14:57:05 richt: we should clarify spec re whether all fields included 14:58:01 Dong-Young_Lee has joined #dap 14:58:10 darobin: phonegap is implemeting read and write? 14:58:21 richt: yes, both 14:58:42 enewland has joined #dap 14:58:47 enewland has left #dap 14:58:58 darobin: read only is one way to avoid quirks 14:59:08 +[IPcaller] 14:59:14 -[IPcaller] 14:59:20 -> http://www.w3.org/mid/23694B98-A35D-4572-8C2A-FA5E00D708D7@nokia.com quirks in Contacts 14:59:39 +??P24 15:00:12 darobin: worth looking at quirks in Android implementation 15:00:49 ... many of them are "not supported" and "will return null" 15:00:54 "In order to save the Contact object on the device call the save method on the Contact object." 15:01:11 Present+ Dong-Young_Lee 15:01:32 -> http://www.w3.org/mid/AANLkTimTRDn=8eXwyY=HFqBSNbYFM4xfeBTU+h3M7PCo@mail.gmail.com save support 15:02:02 ACTION-251? 15:02:02 ACTION-251 -- John Morris to review privacy text related to ISSUE-78 for capture -- due 2010-10-20 -- OPEN 15:02:02 http://www.w3.org/2009/dap/track/actions/251 15:02:15 Topic: Capture 15:02:44 Topic: Gallery 15:02:51 ACTION-216? 15:02:51 ACTION-216 -- WonSuk Lee to reformulate gallery API to look like contacts API -- due 2010-07-21 -- OPEN 15:02:51 http://www.w3.org/2009/dap/track/actions/216 15:03:09 jmorris: re Capture - I will turn to action 251 15:04:11 (I think starting with readonly for gallery makes plenty of sense) 15:04:22 ??: we can look to reuse contacts approach 15:04:36 s/??/Anssi/ 15:04:41 ... we can make major changes to gallery 15:04:54 ... let's proceed with contacts design model 15:05:35 darobin: do we need to wait another week? 15:06:06 -richt 15:06:07 PROPOSED RESOLUTION: move forward with read-only gallery 15:06:13 AnssiK: could we just copy the contacts scheme, with media parts 15:06:39 ... we can move faster if we split into smaller parts 15:06:43 +1 15:06:46 RESOLUTION: move forward with read-only gallery 15:06:46 RESOLUTION: move forward with read-only gallery 15:07:02 Topic: Calendar 15:07:23 Topic: Sysinfo status 15:07:35 darobin: reviewing Sysinfo 15:07:47 ... almost done, finding small nits 15:08:14 ... anything else for call? 15:08:16 zakim, drop thomas 15:08:16 Thomas is being disconnected 15:08:18 -Thomas 15:08:21 -maoteo 15:08:23 -ilkka 15:08:27 -darobin 15:08:28 -Dom 15:08:29 -nwidell 15:08:32 -jmorris 15:08:34 -LauraA 15:08:37 -AnssiK 15:08:41 -fjh 15:08:42 -Claes 15:08:46 rrsagent, generate minutes 15:08:46 I have made the request to generate http://www.w3.org/2010/10/20-dap-minutes.html fjh 15:08:51 -cmarc 15:09:04 fjh_ has joined #dap 15:09:08 -??P24 15:09:10 UW_DAP()10:00AM has ended 15:09:11 Attendees were fjh, +33.2.99.12.aaaa, cmarc, darobin, Dom, Claes, nwidell, ilkka, Thomas, richt, LauraA, AnssiK, enewland, +34.97.421.aabb, danielcoloma, [IPcaller] 15:09:18 generate http://www.w3.org/2010/10/20-dap-minutes.html