Create a Resource Server Profile on top of FAPI 2
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 30/100
Direzione di ricerca
Non sono indicati file o test del repository. Inizia esaminando l’issue e la discussione Bitbucket collegata, quindi confronta il profilo FAPI2 Resource Server o Protected Resource proposto con le linee guida FAPI2 esistenti e gli header x-fapi; il lavoro è completato quando è disponibile una proposta concordata su ambito e requisiti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Originally submitted by M V (Mark Verstege) on 2023-06-19
Whilst FAPI has primarily concerned itself with the security layer for open data ecosystems, FAPI1 also provided requirements for resource servers including x-fapi headers. Based on the discussion here: https://bitbucket.org/openid/fapi/issues/487/rs-must-check-x-fapi-interaction-id-is-an, the x-fapi-interaction-id header is dropped from the core FAPI2 security profile, and may be included as implementation guidance.
The practical reality is that there are common patterns emerging at the resource layer for many implementations that utilise FAPIx. Many of these patterns are built off the FAPI profiles or have opinionated implementation approaches. With the “family of profiles” approach taken with FAPI2, there could be a lot of value developing a baseline resource profile that can be commonly implemented across open data initiatives leveraging opinionated patterns, resource designs and OIDF standards.
This would lend itself to efficiencies and lower implementation costs. Vendors could offer a framework style profile to embed any domain or initiative specific data model into, whilst still extending or constraining based on their needs. It would likely also assist with interoperability in federated ecosystem connections (e.g. GAIN use cases) and cross-border use cases.
FAPI2 Resource Server Profile
I’d be keen to explore a FAPI2 “Resource Server” Profile or “Protected Resource” Profile that could include requirements around resource scaffolding like correlation ids, idempotency patterns for action initiation (e.g. making a payment), data sharing request/response patterns, subscriber and event notification patterns, fraud and risk metadata.
X-FAPI Headers
There is benefit especially with the x-fapi-interaction-id being included which is in wide use as a correlation ID for many implementations. Where implemented, this could then have a set of provisions on implementation following agreed requirements (SHALL).
None of the x-fapi headers have been ported over to FAPI2 implementation guidance. I see less value in some of the other x-fapi headers like x-fapi-auth-date for example, but similar guidance could be helpful.
Bitbucket status: open
Bitbucket origin: issue 607
- Lingua principale
- HTML
- Stelle
- 4
- Fork
- 3
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
-
component: Implementation & Deployment Advice
Difficoltà 2/5 1-3 ore Idoneità per principianti 55/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
Issue simili
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
cosimochellini/one-piece-zero-spoiler#551 ·
I maintainer di solito rispondono entro 1 giorno
-
getWatched() omits __proto__ directories when cwd is setForse già presa @maxazure l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 79/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
bilawalsidhu/gods-eye-view#1060 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
signal18/replication-manager#1981 ·
I maintainer di solito rispondono entro 1 giorno