Authorization Server Registration (sub class of Agent Registration)
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 18/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Domain
- authorization
Research direction
Start with issue #187 and the existing Agent Registration, Access Grant, Data Grant, Grant Registry, and server metadata concepts referenced here. Done requires an agreed Authorization Server Registration model and a resolved way for an AA to discover and track associated Authorization Servers; the issue does not identify implementation files or tests.
Written by the indexing model from the issue text.
Description
We've been discussing how the Authorization Server gets access to Data Grants which are relevant to the Resource Servers associated with it. I would like to consider introducing Authorization Server Registration.
I see this issue related to #187 since we are talking about granting access to specific data grants.
Authorization Server Registration just as any Agent Registration would have and Access Grant. This Access Grant in turn would link to any number of Grant Grant (TODO: rename) instead of Data Grant.
Grant Grant could reference each of the Data Grants with something like hasDataGrant (instead of hasDataInstance). If we see a need to use scopes we could define a new one or reuse SelectedFromRegistry.
I see at least one change that could align Grant Grant more closely with how Data Grant works.
Instead of storing Data Grant in an Agent Registration, they could be stored in a Grant Registry. This way each Access Grant would still be stored in Agent Registration of the grantee, but it would like to Data Grant (same for the Grant Grant) in the Grant Registry. I don't think this change is necessary but it would move us further from relying on a containment hierarchy.
I also see one challenge. Based on Data Grants (specifical value of hasDataRegistration) we can find the Resource Server to which the grant is applicable. Currently, the Authorization Server can be discovered from the as_uri parameter in the WWW-Authenticate header of 401 Unauthorized. I see it as unreliable for 2 reasons:
- Knowledge of IRI denoting a protected resource is needed to get 401 response
- There is no resource for which notifications subscription could be established. AS associated with RS could possibly change at any time.
I think RS (Solid Storage) should advertise its AS in server metadata resource and allow subscribing to it. This way an AA, which manages Authorization Server Registrations, could subscribe to metadata resources of all Resource Servers that it has Data Grants for and keep up-to-date GrantGrants for their corresponding Authorization Servers.
/cc @justinwb @laurensdeb @woutermont
- Dominant language
- Bikeshed
- Stars
- 58
- Forks
- 18
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from solid/data-interoperability-panel
-
solid/data-interoperability-panel#338 · 11 comments · 1 assignee ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
solid/data-interoperability-panel#337 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
solid/data-interoperability-panel#336 · 2 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
solid/data-interoperability-panel#335 · 3 comments ·
-
solid/data-interoperability-panel#334 · 5 comments · 1 assignee ·
All issues in solid/data-interoperability-panel
Similar issues
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
AXERA-TECH/ax-llm#75 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gitbutlerapp/gitbutler#15998 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security impact:ux-friction issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100