W3C

WoT Security

11 January 2021

Attendees

Present
Cristiano_Aguzzi, Elena_Reshetova, Jack_Dickinson, Kaz_Ashimura, Michael_McCool, Tomoaki_Mizushima
Regrets
Oliver
Chair
McCool
Scribe
cris, kaz

Meeting minutes

Prev minutes

Dec-7

approved

Issue 197

Issue 197

McCool: (adds comments)

McCool: do you think that the comment covered all our points?

Elena: I don't any further comments on this.

McCool: I think that it is important to have an action point on this issue. Anyhow if anybody has more comments please go ahead and comment

<kaz> McCool's comment

TD Issue 998

<kaz> TD issue 998

McCool: I feel that an URI template could solve the issue about API keys and PSK security schema

McCool: we could extended the APISecuritySchema adding terms for URI templates

McCool: at the end of the day we have to do a PR.

<kaz> McCool's comments

McCool: I'll try to create a PR before the next TD call

Cristiano: I think this issue relate to another one on TD repo.

McCool:
… I think 923 is another issue, but I'll note it down.
… about 923 we could cover it by adding a "template" key in the "in" field of API security schema

Cristiano: I agree, it should work and cover also the query use case.

McCool: I prefer to leave the query parameter to avoid backward compatibility problems.

Cristiano: right

Cristiano: about OAuth 2 we probably need more concrete use cases to asses its variability.

McCool: I'll mark also the 923 as PR needed and I'll keep it mind while working on the next PR.

<kaz> TD Issue 923

McCool: ok, let's close the meeting.

<kaz> [adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 127 (Wed Dec 30 17:39:58 2020 UTC).