Create a Resource Server Profile on top of FAPI 2
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
Research direction
No repository files or tests are named. Start by reviewing the issue and the linked Bitbucket discussion, then map the proposed FAPI2 Resource Server or Protected Resource profile against existing FAPI2 guidance and the x-fapi headers; done means an agreed scope and requirements proposal.
Written by the indexing model from the issue text.
Description
Originally submitted by M V (Mark Verstege) on 2023-06-19
Whilst FAPI has primarily concerned itself with the security layer for open data ecosystems, FAPI1 also provided requirements for resource servers including x-fapi headers. Based on the discussion here: https://bitbucket.org/openid/fapi/issues/487/rs-must-check-x-fapi-interaction-id-is-an, the x-fapi-interaction-id header is dropped from the core FAPI2 security profile, and may be included as implementation guidance.
The practical reality is that there are common patterns emerging at the resource layer for many implementations that utilise FAPIx. Many of these patterns are built off the FAPI profiles or have opinionated implementation approaches. With the “family of profiles” approach taken with FAPI2, there could be a lot of value developing a baseline resource profile that can be commonly implemented across open data initiatives leveraging opinionated patterns, resource designs and OIDF standards.
This would lend itself to efficiencies and lower implementation costs. Vendors could offer a framework style profile to embed any domain or initiative specific data model into, whilst still extending or constraining based on their needs. It would likely also assist with interoperability in federated ecosystem connections (e.g. GAIN use cases) and cross-border use cases.
FAPI2 Resource Server Profile
I’d be keen to explore a FAPI2 “Resource Server” Profile or “Protected Resource” Profile that could include requirements around resource scaffolding like correlation ids, idempotency patterns for action initiation (e.g. making a payment), data sharing request/response patterns, subscriber and event notification patterns, fraud and risk metadata.
X-FAPI Headers
There is benefit especially with the x-fapi-interaction-id being included which is in wide use as a correlation ID for many implementations. Where implemented, this could then have a set of provisions on implementation following agreed requirements (SHALL).
None of the x-fapi headers have been ported over to FAPI2 implementation guidance. I see less value in some of the other x-fapi headers like x-fapi-auth-date for example, but similar guidance could be helpful.
Bitbucket status: open
Bitbucket origin: issue 607
- Dominant language
- HTML
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
component: Certification component: FAPI2: Advanced Authorization
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
component: Certification component: FAPI2: Security Profile
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
external-issue to-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
googleapis/google-cloud-swift#1151 ·
-
external
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
langchain-ai/langgraph#9074 · 1 comment ·
-
documentation specification
Difficulty 1/5 Under an hour Newbie friendliness 90/100
openai/openai-openapi#584 ·