[{"author": "Danny Zollner", "text": "

I can help with 2/3rds..

", "time": "2023-03-28T08:00:37Z"}, {"author": "Danny Zollner", "text": "

just not so much on the 20 mins I've got :)

", "time": "2023-03-28T08:00:44Z"}, {"author": "Danny Zollner", "text": "

Yes

", "time": "2023-03-28T08:01:13Z"}, {"author": "Nancy Cam-Winget", "text": "

Of course, we will basically tag team

", "time": "2023-03-28T08:01:18Z"}, {"author": "Joris Baum", "text": "

Hello!

", "time": "2023-03-28T08:04:35Z"}, {"author": "Anthony Nadalin", "text": "

What happened to the sso trigger?

", "time": "2023-03-28T08:16:57Z"}, {"author": "Joris Baum", "text": "

As far as I understood the use cases are less concrete than in rfc7642. So it does not contain any notion of specific use cases like SSO triggers?

", "time": "2023-03-28T08:20:32Z"}, {"author": "Anthony Nadalin", "text": "

Worried about direction of the updates as we made 7642 very specific

", "time": "2023-03-28T08:22:31Z"}, {"author": "Anthony Nadalin", "text": "

Why is alg=none supported as there are hacking issues associated with this

", "time": "2023-03-28T08:26:48Z"}, {"author": "Anthony Nadalin", "text": "

Suggest the registry just be documented in the spec

", "time": "2023-03-28T08:28:43Z"}, {"author": "Eliot Lear", "text": "

Mic not working

", "time": "2023-03-28T08:31:07Z"}, {"author": "Anthony Nadalin", "text": "

I don't understand why statefull is not required ?

", "time": "2023-03-28T08:35:56Z"}, {"author": "Anthony Nadalin", "text": "

It's going still caus security issues with DoS

", "time": "2023-03-28T08:37:22Z"}, {"author": "Anthony Nadalin", "text": "

Alternative mechanism should not mean less security

", "time": "2023-03-28T08:44:44Z"}, {"author": "Phillip Hunt", "text": "

:grinning: Hi Tony!

", "time": "2023-03-28T08:45:07Z"}, {"author": "Anthony Nadalin", "text": "

Phillip Hunt said:

\n
\n

:grinning: Hi Tony!

\n
\n

:smile:

", "time": "2023-03-28T08:46:43Z"}, {"author": "Danny Zollner", "text": "

Anthony - the intent of not requiring stateful attribute-level snapshots of resources is to reduce the compute resource (so.. memory) footprint required there. Snapshot at the resource level of what resources need to be returned, not at the attribute level.

", "time": "2023-03-28T08:48:05Z"}, {"author": "Danny Zollner", "text": "

I don't think those of us who've been working on the draft recently have identified any security concerns with it - we should have a new version out of the draft next week, so perhaps once we publish that if you still believe there to be security concerns could you call them out and explain on the mailing list?

", "time": "2023-03-28T08:49:15Z"}, {"author": "Anthony Nadalin", "text": "

Danny the result has to be stateful

", "time": "2023-03-28T08:49:46Z"}, {"author": "Phillip Hunt", "text": "

For events, alg=none is really intended for internal cluster (e.g., k8s) or secure network communications in a data center. The spec still requires transfer over TLS. We could add more commentary in security considerations (or drop it).

", "time": "2023-03-28T08:50:05Z"}, {"author": "Phillip Hunt", "text": "

I don't think \"intent\" of the scim programmer carries much weight if the database being used only does stateful or locking cursors.

", "time": "2023-03-28T08:50:48Z"}, {"author": "Phillip Hunt", "text": "

sure

", "time": "2023-03-28T08:54:01Z"}, {"author": "Eliot Lear", "text": "

thanks all

", "time": "2023-03-28T08:57:16Z"}, {"author": "Danny Zollner", "text": "

Thanks everyone

", "time": "2023-03-28T08:57:21Z"}, {"author": "David Waite", "text": "

zzz

", "time": "2023-03-28T08:57:28Z"}, {"author": "Phillip Hunt", "text": "

Thanks everyone!

", "time": "2023-03-28T08:57:31Z"}]