Do clients really need access to their Grants/Authorizations?

Open
#315 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
20/100
Issue type
Refactor
Clarity
Needs clarification
Activity status
Stale

Research direction

Start by reading the linked data-interoperability-panel issue 308 and comparing its proposal with the OAuth 2.x, UMA, and GNAP authorization models mentioned here. Determine which grantee use cases require direct access to authorization or grant information, and document whether the specification should retain or remove that access.

Written by the indexing model from the issue text.

Description

In light of data-interoperability-panel/issues/308 (giving grantees access to Authorizations), I wondered which use cases actually need grantees to directly access permission info (authorizations/grants, denials etc.) at all ... Afaik, none of our reference AS frameworks (OAuth 2.x, UMA, GNAP) support that; if a client wants to know whether it is allowed to access some resource, it can always try to get a token. After all, upon discovery of existing authorization, that's what the client would do anyway. Leaving direct access out would thus simplify our model, and bring it closer to existing AS implementations.

Dominant language
Bikeshed
Stars
58
Forks
18
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from solid/data-interoperability-panel

All issues in solid/data-interoperability-panel

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.