13:56:53 RRSAgent has joined #wot-discovery 13:56:53 logging to https://www.w3.org/2022/05/30-wot-discovery-irc 13:56:59 meeting: WoT Discovery 13:57:39 chair: McCool 13:57:50 present+ Kaz_Ashimura, Michael_McCool 14:00:31 Mizushima has joined #wot-discovery 14:02:28 agenda: https://www.w3.org/WoT/IG/wiki/WG_WoT_Discovery_WebConf#30_May_2022 14:02:34 present+ Kunihiko_Toumura 14:02:46 ktoumura has joined #wot-discovery 14:04:24 agenda: https://www.w3.org/WoT/IG/wiki/WG_WoT_Discovery_WebConf#30_May_2022 14:04:41 present+ Farshid_Tavakolizadeh, Tomoaki_Mizushima 14:05:48 FarshidT has joined #wot-discovery 14:05:55 scribenick: kaz 14:06:08 topic: Minutes 14:06:17 -> https://www.w3.org/2022/05/23-wot-discovery-minutes.html May-23 14:08:49 approved 14:09:04 topic: Discovery Explainer 14:09:38 -> https://github.com/w3c/wot-discovery/pull/309 PR 309 - Draft Explainer 14:09:49 mm: question on HTTP or not 14:10:03 cris__ has joined #wot-discovery 14:10:21 ... we're not sure about how to use CoAP 14:10:35 ... think we should do HTTP only now 14:10:49 ... could add CoAP once we get a PR 14:12:27 ... my proposed resolution is leave it asis 14:12:31 (no objections) 14:14:26 mm: (goes through the changes) 14:14:48 -> https://github.com/w3c/wot-discovery/pull/309/files Files changed 14:15:33 ft: looks OK 14:17:13 mm: (visits Cristiano's comment) 14:17:33 -> https://github.com/w3c/wot-discovery/pull/309/files#r884760454 Cristiano's comment 14:17:44 ca: I'm OK with this PR 14:17:50 mm: ok 14:17:59 ... (fixes some typos) 14:19:06 ... (shows Farshid's proposed changes) 14:19:20 -> https://github.com/w3c/wot-discovery/pull/309/files#r882077369 Farshid's proposed changes 14:19:34 ft: you can go ahead and merge the PR 309 14:21:48 mm: objection to merge this PR? 14:21:50 (none) 14:22:08 mm: we can add further changes later 14:22:28 (merged) 14:23:42 topic: PRs 14:23:55 subtopic: PR 317 14:24:11 -> https://github.com/w3c/wot-discovery/pull/317 PR 317 - Internationalization Questionnaire updates 14:24:21 mm: would merge this PR as well 14:25:09 ... any objections? 14:25:47 (none) 14:25:47 merged 14:25:59 subtopic: PR 322 14:26:16 -> https://github.com/w3c/wot-discovery/pull/322 PR 322 - Suppress Unused Dfns Respec Error 14:26:28 mm: suppressing the errors from ReSpec 14:26:31 merged 14:26:46 subtopic: PR 313 14:27:12 -> https://github.com/w3c/wot-discovery/pull/313 PR 313 - Security Bootstrapping 14:27:19 mm: a bit difficult one 14:28:08 ... (goes through the discussion on the PR) 14:29:04 ... related to onboarding discussion 14:29:15 ... but we don't have spec for onboarding 14:30:59 -> https://pr-preview.s3.amazonaws.com/mmccool/wot-discovery/pull/313.html#exploration-secboot Preview - 7.1.2 Security Bootstrapping 14:32:26 mm: added edit for "Security bootstrapping MAY be provided on any HTTP endpoint that serves a TD." 14:33:19 ... (goes through the updated assertions) 14:36:29 ... (also shows Mozilla's MDN document on HTTP Authentication) 14:36:48 -> https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#the_general_http_authentication_framework MDN Web Docs - HTTP Authentication 14:38:39 mm: (then describes the error code section) 14:39:09 ... just in general, do you feel major fixes still needed? 14:39:13 ft: looks good now 14:39:31 mm: small fixes are appropriate 14:39:42 q? 14:40:11 ca: we can merge this PR and then continue to work on the Explainer, etc. 14:40:37 https://github.com/w3c/wot-discovery/pull/313/files#diff-0eb547304658805aad788d320f10bf1f292797b5e6d745a3bf617584da017051R947 14:40:53 ... but wondering about some assertion above 14:41:52 mm: The server MUST respond with the requested TD only after performing necessary authentication and authorization? 14:42:13 ca: yeah 14:42:25 ft: could say something else instead 14:42:44 mm: I know it's tricky 14:44:01 ... which line for that assertion? 14:44:21 ca: 947 14:44:31 mm: (goes to line 947) 14:44:47 ... (and edits the text) 14:45:08 ... (for the assertion "self-http-access-control") 14:45:39 ... If authentication and authorization are necessary 14:45:57 ... they MUST be performed before the server... 14:46:09 ... next thing is the respond codes 14:46:50 ... If the OAuth2 code flow is used during security bootstrapping 14:47:16 ... the "302 (Found)" or "303 (See Other)" response code MUST be... 14:47:24 ... what other changes needed? 14:47:58 ... (fixes some more typos) 14:49:46 ... (then goes through the remaining comments on the PR) 14:50:28 ... onboarding is kind of out of scope 14:51:03 -> https://github.com/w3c/wot-discovery/pull/313#issuecomment-1141235764 Ben's comments 14:51:09 s/comments /comments/ 14:52:11 mm: (adds responses) 14:52:20 ... Ben's point is something I also worry about 14:52:33 ... but don't want to weaken security generally 14:52:47 ... think we should merge this PR now 14:53:02 ... and think about other ways to address this 14:53:32 ... making security bootstrapping mandatory in some profiles would be one way 14:54:14 ... another way would be to define an onboarding process 14:54:28 ... any objections to merge this PR itself? 14:54:56 (none) 14:54:58 merged 15:01:14 rrsagent, make log public 15:01:20 rrsagent, draft minutes 15:01:20 I have made the request to generate https://www.w3.org/2022/05/30-wot-discovery-minutes.html kaz 15:01:35 topic: PR 323 15:01:48 -> https://github.com/w3c/wot-discovery/pull/323 PR 323 - Update Discovery overview figure and Architecture section 15:02:10 mm: (shows the overview diagram on his local PC) 15:05:59 q? 15:06:02 q+ 15:06:06 q+ 15:07:24 kaz: note we're out of time 15:07:44 mm: would extend the call by 30 mins to get conclusion today 15:07:46 kaz: ok 15:08:54 ack c 15:08:59 ack k 15:12:08 mm: any objections to merge the PR? 15:12:09 (none) 15:12:11 merged 15:13:10 topic: PR 326 15:13:33 -> https://github.com/w3c/wot-discovery/pull/326 PR 326 - Self-Discovery Cleanup 15:14:17 mm: these descriptions are all about the HTTP section 15:14:56 ca: wondering about the relationship with the Issue 315 15:15:35 -> https://github.com/w3c/wot-discovery/issues/315 Issue 315 - Return charset parameter in content-type 15:15:53 mm: need a PR for that 15:16:11 ... regarding the spelling for the spec, we usually use American spelling 15:17:07 ... (got conflicts for PR 326) 15:17:19 ... (and try to resolve them) 15:18:50 ... any objections to merge this? 15:18:58 (none) 15:19:00 merged 15:20:05 topic: WD publication 15:20:39 mm: (creates a branch named "review-pre-cr-wd" for the WD publication) 15:20:49 ... we need a resolution during the main call 15:21:48 proposal: start review process and request a resolution in the main call in two weeks to publish branch review-pre-cr-wd as a WD to be used for wide review; also refer to this branch for now in review requests 15:24:28 resolution: start review process and request a resolution in the main call in two weeks to publish branch review-pre-cr-wd as a WD to be used for wide review; also refer to this branch for now in review requests 15:27:22 mm: PR 325 to be discussed next time 15:27:33 -> https://github.com/w3c/wot-discovery/pull/325 PR 325 - Service exploration 15:27:35 [adjourned] 15:27:40 rrsagent, draft minutes 15:27:40 I have made the request to generate https://www.w3.org/2022/05/30-wot-discovery-minutes.html kaz 17:40:36 zkis has joined #wot-discovery 21:18:36 zkis has joined #wot-discovery 21:33:36 zkis has joined #wot-discovery 21:47:36 zkis_ has joined #wot-discovery