Do clients really need access to their Grants/Authorizations?
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Refactor
- Clarity
- Needs clarification
- Activity status
- Stale
- Domain
- authorization, security
Research direction
Start by reading the linked data-interoperability-panel issue 308 and comparing its proposal with the OAuth 2.x, UMA, and GNAP authorization models mentioned here. Determine which grantee use cases require direct access to authorization or grant information, and document whether the specification should retain or remove that access.
Written by the indexing model from the issue text.
Description
In light of data-interoperability-panel/issues/308 (giving grantees access to Authorizations), I wondered which use cases actually need grantees to directly access permission info (authorizations/grants, denials etc.) at all ... Afaik, none of our reference AS frameworks (OAuth 2.x, UMA, GNAP) support that; if a client wants to know whether it is allowed to access some resource, it can always try to get a token. After all, upon discovery of existing authorization, that's what the client would do anyway. Leaving direct access out would thus simplify our model, and bring it closer to existing AS implementations.
- Dominant language
- Bikeshed
- Stars
- 58
- Forks
- 18
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from solid/data-interoperability-panel
-
solid/data-interoperability-panel#338 · 11 comments · 1 assignee ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
solid/data-interoperability-panel#337 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
solid/data-interoperability-panel#336 · 2 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
solid/data-interoperability-panel#335 · 3 comments ·
-
solid/data-interoperability-panel#334 · 5 comments · 1 assignee ·
All issues in solid/data-interoperability-panel
Similar issues
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
AXERA-TECH/ax-llm#75 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gitbutlerapp/gitbutler#15998 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security impact:ux-friction issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100