sandro
present+ sandro
tantek
tantek
hmm - I didn't see anyone create
aaronpk
tantek
tantek
no official telcon today, but we are unofficially on the call discussing
ben_thatmustbeme
cwebber
ben_thatmustbeme
cwebber
I didn't hear
I didn't hear
18:10:32 [cwebber]
was plugging in my headphones
sandro
18:12:11 [tantek]
Proposing inserting second bullet point to 4.1:
18:12:26 [tantek]
• Receivers MUST verify Webmentions per section 3.2.2
18:12:27 [ben_thatmustbeme]
yeah, i think that makes sense.
18:14:06 [tantek]
Also, move "* Receviers MAY periodically..." to the end of the list
18:15:41 [ben_thatmustbeme]
yes, change 'publish' to 'display'
ben_thatmustbeme
ben_thatmustbeme
18:16:44 [ben_thatmustbeme]
i don't see anything about re-verify anywhere
18:16:59 [aaronpk]
that's a different CSRF
18:17:10 [tantek]
And also, reword "* If a receiver chooses to publish ..." to "* If a receiver chooses to display ..." and move it to right before "* Receivers MAY moderate ..."
18:21:19 [ben_thatmustbeme]
cors uses non-normative for CSRF
18:21:20 [cwebber]
sounds good to me, I don't think we need a resolution here either
18:22:05 [aaronpk]
haha wat. that's an informative reference to an email in a mailing list?!
Loqi
ben_thatmustbeme
yeah.... :/
yeah.... :/
ben_thatmustbeme even this ... thing. doesn't even have any references to CSRF or XSS
18:23:52 [Loqi]
[David Ross] Entry Point Regulation
18:24:19 [aaronpk]
this looks like a pretty good reference
18:24:32 [tantek]
hey this looks better :P
cwebber
ben_thatmustbeme
18:25:16 [cwebber]
pretty well known secuity site
cwebber
no I have :)
no I have :)
18:25:33 [ben_thatmustbeme]
i have heard of it before as well
ben_thatmustbeme
only in passing
only in passing
sandro
ben_thatmustbeme
ben_thatmustbeme
2.84.14 lol
2.84.14 lol
ben_thatmustbeme
thats a lot of ... yeah
thats a lot of ... yeah
tantek
sandro
ben_thatmustbeme
ben_thatmustbeme
18:28:13 [ben_thatmustbeme]
and no, i could not find anything referenced for XSS
sandro might be more robust
ben_thatmustbeme
thats the same page
thats the same page
ben_thatmustbeme
aaronpk
18:33:43 [ben_thatmustbeme]
i feel like the security group should publish some note explaining such things, just so there is a normative reference to it
aaronpk
18:34:05 [tantek]
I think it's better to cite the expanded URL, the expansion makes it more readable even without clicking
aaronpk
ben_thatmustbeme
ben_thatmustbeme
aaronpk
18:43:22 [ben_thatmustbeme]
"have we finished bikeshedding 4.1 yet" ~tantek just before bikeshedding order more
ben_thatmustbeme
18:44:47 [tantek]
ben_thatmustbeme: what I was talking to myself included ;)
18:45:05 [tantek]
(this is what chairing does to your brain)
18:46:58 [ben_thatmustbeme]
yes, aaronpk is an overachiever
aaronpk
ben_thatmustbeme
tantek
sandro
cwebber
+1 seems good
+1 seems good
18:50:51 [aaronpk]
editor's draft is updated
tantek
aaronpk
19:00:09 [ben_thatmustbeme]
we had said we would do them once a month in the new year
19:00:46 [ben_thatmustbeme]
+1 for a meeting next week and starting that as our one for the month
19:01:46 [cwebber]
I'll be around next week
19:01:56 [sandro]
aaronpk, let me know when the 1/5 draft is staged....
19:02:11 [aaronpk]
it's there. same URLs as before.
19:03:01 [ben_thatmustbeme]
cwebber: can you be on earlier next week?
ben_thatmustbeme
just making sure
just making sure
19:03:24 [cwebber]
central time, and I can be on earlier
19:03:44 [cwebber]
could we do 2 hours earler?
19:05:12 [ben_thatmustbeme]
2 hours earlier could work for me
19:05:28 [cwebber]
I mean, I could also do 2.5 hours earlier :P
19:05:31 [ben_thatmustbeme]
someone should email evan and julien
ben_thatmustbeme
19:06:19 [cwebber]
current time is during lunchtime for me :)
19:06:22 [cwebber]
so moving it back works
19:06:48 [ben_thatmustbeme]
cwebber, yeah, most weeks i am eating during the meeting
19:07:17 [cwebber]
I'm not usually eating, though during boring parts sometimes I do unload the dishwasher ;)
19:11:25 [tantek]
logged an informal summary here:
ben_thatmustbeme
19:12:03 [ben_thatmustbeme]
since the change is mainly for her
19:12:12 [ben_thatmustbeme]
and it may break schedules for others
19:14:17 [ben_thatmustbeme]
go go go, first REC of the new year
ben_thatmustbeme
19:15:44 [Loqi]
[Steve Faulkner] Accessible Rich Internet Applications in HTML
ben_thatmustbeme
oj, just WD
oj, just WD
ben_thatmustbeme
ben_thatmustbeme
and searching for 2017
and searching for 2017
ben_thatmustbeme
ben_thatmustbeme
19:18:44 [tantek]
I've taken the CSS logo on complaints to #css
19:18:50 [tantek]
to see if anyone there is paying attention
19:37:23 [tantek]
aside: this is pretty cool
