W3C

– DRAFT –
WoT Security

26 September 2022

Attendees

Present
Jan_Romann, Kaz_Ashimura, Michael_McCool, Philipp_Blum
Regrets
-
Chair
McCool
Scribe
citrullin

Meeting minutes

Minutes review

McCool: Any objections to the minutes? No objections.

Minutes

Discovery issues

<kaz> wot-discovery issues with the "Security" label

McCool: At this point we may have to defer them to WoT 2.0 (wot-discovery issues flagged with security)

Discovery issue 185

<kaz> wot-discovery issue 185 - OAuth2 and SSE Notificiations

McCool: The SSE topic is an interesting topic. Any input on this?

Philipp: Sorry, I am not familiar with SSE. I have to look into it first.

McCool: It's a combination of two complicated topics. oAuth and SSE. Farshid has some useful comments.

oAuth 2 and SSE Notification

<McCool> https://github.com/w3c/wot-discovery/issues/185#issue-900858578 - farshid's comments on SSE and OAuth2

mm adds a comment

Thing Description security issues

TD issue 949

<kaz> wot-thing-description issue 949 - We need extension ontology to include implicit and password flows in OAuth2

McCool: We have to publish an ontology. Kaz, how do we do this?

Kaz: There are several ways to do it. Registry track may be one of them. Or we host the ontology ourself on the w3 domain. I think it depends on how we want to maintain the resources. We might want to talk with PLH as well after clarifying our own expectations.

McCool: We agreed to just leave it alone for now. There was a lot of discussions about this.

mm adds a comment to the issue

TD issue 998

wot-thing-description issue 998 - API key and PSK security schemes are not referenced or explained

<kaz> WoT Thing Description - 5.3.3.9 PSKSecurityScheme

<kaz> td-vocab-identity--PSKSecurityScheme has two implementations already

mm adds comment, proposed closing

<kaz> [adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 192 (Tue Jun 28 16:55:30 2022 UTC).