[{"author": "Francesca Palombini", "text": "<p>Hi Julian!</p>", "time": "2023-03-28T06:30:00Z"}, {"author": "Julian Reschke", "text": "<p>the agenda buttons for the notepad and the full video client seem to be off by one row (in Firefox)</p>", "time": "2023-03-28T06:32:27Z"}, {"author": "Julian Reschke", "text": "<p>clicking them takes me to \"tigress\"</p>", "time": "2023-03-28T06:32:38Z"}, {"author": "Chris Lemmons", "text": "<p>I've experienced that in the past with Chrome.</p>", "time": "2023-03-28T06:33:02Z"}, {"author": "Francesca Palombini", "text": "<p>oh really? full video worked fine on chrome</p>", "time": "2023-03-28T06:33:05Z"}, {"author": "Julian Reschke", "text": "<p>thanks, Justin</p>", "time": "2023-03-28T06:40:48Z"}, {"author": "Julian Reschke", "text": "<p>FWIW, this was about <a href=\"https://github.com/httpwg/http-extensions/issues/2417\">https://github.com/httpwg/http-extensions/issues/2417</a></p>", "time": "2023-03-28T06:40:59Z"}, {"author": "Martin Thomson", "text": "<p>Why are service workers doing service function chaining?</p>", "time": "2023-03-28T06:42:17Z"}, {"author": "Martin Thomson", "text": "<p>and why is a cookie spec talking about that?</p>", "time": "2023-03-28T06:42:36Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention\" data-user-id=\"26\">@Martin Thomson</span> because MASQUE.</p>", "time": "2023-03-28T06:43:19Z"}, {"author": "Tommy Pauly", "text": "<p>Why masque?</p>", "time": "2023-03-28T06:43:54Z"}, {"author": "Lucas Pardue", "text": "<p>huh</p>", "time": "2023-03-28T06:43:58Z"}, {"author": "Benjamin Schwartz", "text": "<p>(This is a joke.  \"SFC\" in the slides is \"Site for Cookies\".)</p>", "time": "2023-03-28T06:45:25Z"}, {"author": "Tommy Pauly", "text": "<p>Heh =)</p>", "time": "2023-03-28T06:46:49Z"}, {"author": "Chris Lemmons", "text": "<p>Inner lists aren't valid parameter values, iirc.</p>", "time": "2023-03-28T07:00:11Z"}, {"author": "Lucas Pardue", "text": "<p>what Chris said</p>", "time": "2023-03-28T07:01:13Z"}, {"author": "Tommy Pauly", "text": "<p>That may be why I didn't use that =)</p>", "time": "2023-03-28T07:01:30Z"}, {"author": "Julian Reschke", "text": "<p>maybe a whitespace (SP) delimited list would be better here</p>", "time": "2023-03-28T07:01:38Z"}, {"author": "Mark Nottingham", "text": "<p>Ah, that's right</p>", "time": "2023-03-28T07:02:22Z"}, {"author": "Tommy Pauly", "text": "<p>Yeah:<br>\nparam-value   = bare-item</p>", "time": "2023-03-28T07:02:35Z"}, {"author": "Lucas Pardue", "text": "<p>any format changes now would break deployments, I'm not sure how you'd coordinate that</p>", "time": "2023-03-28T07:02:44Z"}, {"author": "Mark Nottingham", "text": "<p>different name</p>", "time": "2023-03-28T07:02:54Z"}, {"author": "Tommy Pauly", "text": "<p>Well we could coordinate easily enough, not an issue</p>", "time": "2023-03-28T07:03:03Z"}, {"author": "Lucas Pardue", "text": "<p>I'd have to send both headers /groan</p>", "time": "2023-03-28T07:03:18Z"}, {"author": "Tommy Pauly", "text": "<p>But I'm not sure that a whitespace separated list is notably more useful than comma-separated</p>", "time": "2023-03-28T07:03:23Z"}, {"author": "Lucas Pardue", "text": "<p><span aria-label=\"point up\" class=\"emoji emoji-1f446\" role=\"img\" title=\"point up\">:point_up:</span></p>", "time": "2023-03-28T07:03:40Z"}, {"author": "Julian Reschke", "text": "<p>How common is SP in a DNS name?</p>", "time": "2023-03-28T07:04:01Z"}, {"author": "Tommy Pauly", "text": "<p>(Lucas, you would just send the new format in the existing name and the old client would just deal with failing parsing.)</p>", "time": "2023-03-28T07:04:05Z"}, {"author": "Tommy Pauly", "text": "<p>Commas and SP are both essentially never in a DNS name</p>", "time": "2023-03-28T07:04:18Z"}, {"author": "Christopher Wood", "text": "<p>@Ben: what was the rationale to use a new header name for this?</p>", "time": "2023-03-28T07:04:23Z"}, {"author": "Lucas Pardue", "text": "<p>fair tommy</p>", "time": "2023-03-28T07:04:29Z"}, {"author": "Christopher Wood", "text": "<p>(I missed what David said at the mic)</p>", "time": "2023-03-28T07:04:30Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention\" data-user-id=\"128\">@Christopher Wood</span> There was always a new header name.  My comment was that this header should share the auth \"scheme\" namespace with WWW-Authenticate, which supports a wider range of use cases.</p>", "time": "2023-03-28T07:05:20Z"}, {"author": "Christopher Wood", "text": "<p><span class=\"user-mention\" data-user-id=\"2424\">@Benjamin Schwartz</span> got it. What're your thoughts on just using the existing header names?</p>", "time": "2023-03-28T07:06:54Z"}, {"author": "Jonathan Lennox", "text": "<p>Hash Function Textual Names come from TLS certificate fingerprints in SDP.</p>", "time": "2023-03-28T07:07:42Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention\" data-user-id=\"128\">@Christopher Wood</span> I don't have a strong opinion on that.  I think \"Unprompted-Authentication\" might be helpful to a person trying to understand query logs, but functionally I don't think it is necessary.</p>", "time": "2023-03-28T07:08:51Z"}, {"author": "Christopher Wood", "text": "<p><span aria-label=\"+1\" class=\"emoji emoji-1f44d\" role=\"img\" title=\"+1\">:+1:</span></p>", "time": "2023-03-28T07:09:02Z"}, {"author": "Jonathan Hoyland", "text": "<p>RSA-PSS makes me sad</p>", "time": "2023-03-28T07:11:03Z"}, {"author": "Martin Thomson", "text": "<p>alg=none is amaaaAAAaaazing</p>", "time": "2023-03-28T07:11:24Z"}, {"author": "Jonathan Hoyland", "text": "<p>It's certainly easy to implement correctly</p>", "time": "2023-03-28T07:11:49Z"}, {"author": "Julian Reschke", "text": "<p>or \"norway\" (YAML)</p>", "time": "2023-03-28T07:12:01Z"}, {"author": "Martin Thomson", "text": "<p><a href=\"https://httpwg.org/http-extensions/draft-ietf-httpbis-message-signatures.html#name-initial-contents\">https://httpwg.org/http-extensions/draft-ietf-httpbis-message-signatures.html#name-initial-contents</a> seems pretty solid</p>", "time": "2023-03-28T07:14:18Z"}, {"author": "Martin Thomson", "text": "<p>though I might like to discourage rsa-v1_5-sha256 use</p>", "time": "2023-03-28T07:14:43Z"}, {"author": "Jonathan Hoyland", "text": "<p>Cutting HMACs would probably make a formal analysis easier.</p>", "time": "2023-03-28T07:16:32Z"}, {"author": "Martin Thomson", "text": "<p>probably a lot easier</p>", "time": "2023-03-28T07:16:59Z"}, {"author": "Martin Thomson", "text": "<p>we would want to only take recommended schemes from TLS</p>", "time": "2023-03-28T07:17:11Z"}, {"author": "Chris Lemmons", "text": "<p>+1</p>", "time": "2023-03-28T07:17:50Z"}, {"author": "Julian Reschke", "text": "<p>+1</p>", "time": "2023-03-28T07:18:34Z"}, {"author": "Alan Frindell", "text": "<p>Switching to Authorization header does give you better compression properties</p>", "time": "2023-03-28T07:18:42Z"}, {"author": "Martin Thomson", "text": "<p>No concern, except that the Authorization header is pure jank from a syntactic perspective.</p>", "time": "2023-03-28T07:18:55Z"}, {"author": "Chris Lemmons", "text": "<p>The only situation that would cause a problem here is if you somehow wanted to include both Authorization AND Unprompted-Authorization. I'm not sure that's a real use case, though.</p>", "time": "2023-03-28T07:19:12Z"}, {"author": "Tommy Pauly", "text": "<p>Total jank, yes</p>", "time": "2023-03-28T07:19:50Z"}, {"author": "Jonathan Lennox", "text": "<p>Doesn't Digest need the challenge in the 401?</p>", "time": "2023-03-28T07:21:22Z"}, {"author": "Chris Lemmons", "text": "<p>We don't want the text here to make readers assume that it's creating an exclusive situation.</p>", "time": "2023-03-28T07:22:11Z"}, {"author": "Julian Reschke", "text": "<p>FWIW: I'm looking into revising Basic soonish to clarify the UTF-8 changes that happened lately</p>", "time": "2023-03-28T07:22:16Z"}, {"author": "Lucas Pardue", "text": "<p>lets call is spontaneous compunction</p>", "time": "2023-03-28T07:23:38Z"}, {"author": "Mark Thomas", "text": "<p>I don't believe you can do DIGEST unprompted.</p>", "time": "2023-03-28T07:24:59Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention\" data-user-id=\"453\">@Jonathan Hoyland</span> Nit: It's the other way: Channel-bound auth _to_ the proxy is fine.</p>", "time": "2023-03-28T07:25:46Z"}, {"author": "Martin Thomson", "text": "<p><span class=\"user-mention\" data-user-id=\"2202\">@Mark Thomas</span> yeah, you need a challenge</p>", "time": "2023-03-28T07:25:57Z"}, {"author": "Tommy Pauly", "text": "<p>Right it's auth to the proxy</p>", "time": "2023-03-28T07:25:57Z"}, {"author": "Martin Thomson", "text": "<p>but if the idea is that you got the challenge from elsewhere and the server is OK with that, then I guess we're fine</p>", "time": "2023-03-28T07:26:23Z"}, {"author": "Jonathan Hoyland", "text": "<p>And the backend server doesn't know if it succeeded</p>", "time": "2023-03-28T07:26:26Z"}, {"author": "Martin Thomson", "text": "<p>that's not really a protocol per se, but more of a private arrangement, which is very much in the spirit of the draft, but unnecessary for us to standardize</p>", "time": "2023-03-28T07:27:03Z"}, {"author": "Martin Thomson", "text": "<p>You can't <em>get</em> the stream ID in most cases</p>", "time": "2023-03-28T07:28:39Z"}, {"author": "Mark Nottingham", "text": "<p>see also <a href=\"https://github.com/httpwg/http-extensions/issues/2280\">https://github.com/httpwg/http-extensions/issues/2280</a></p>", "time": "2023-03-28T07:28:57Z"}, {"author": "Mark Nottingham", "text": "<p>(re syntax)</p>", "time": "2023-03-28T07:29:01Z"}, {"author": "Martin Thomson", "text": "<p>my response to Kazuho was \"...but what does Realm even mean?\"</p>", "time": "2023-03-28T07:32:14Z"}, {"author": "Lucas Pardue", "text": "<p>Chris <a href=\"/user_uploads/2/16/Pxg7qBWJXntFMpB-_joP4EFq/image.png\">image.png</a></p>\n<div class=\"message_inline_image\"><a href=\"/user_uploads/2/16/Pxg7qBWJXntFMpB-_joP4EFq/image.png\" title=\"image.png\"><img src=\"/user_uploads/2/16/Pxg7qBWJXntFMpB-_joP4EFq/image.png\"></a></div>", "time": "2023-03-28T07:32:46Z"}, {"author": "Francesca Palombini", "text": "<p>thank you! bye</p>", "time": "2023-03-28T07:32:48Z"}, {"author": "Martin Thomson", "text": "<p><span class=\"user-mention\" data-user-id=\"29\">@David Schinazi</span> re key reuse and context strings: por que no los dos</p>", "time": "2023-03-28T07:32:52Z"}]