HTTPAPI AT IETF 116

Minutes: https://codimd.ietf.org/notes-ietf-116-httpapi

Administrivia

Chat log (raw JSON) is at https://datatracker.ietf.org/meeting/116/materials/chatlog-116-httpapi-202303271300-00

WG Documents - Status Update

Another issue Erik noticed post-IESG review, body text in 400 status responses doesn't really much best practice. Will do a PR and show on mailing list.

Austin: I suggested sorry lost network

MNot: Do we need to change the XML serialization to be more comprehensive?

To be confirmed on list, stick with STD- and document XML serialization limitations.

To confirm, we want to RECOMMEND .yaml over .yml

WG Document Presentations

Justin: as someone coming from the outside, UUIDs as binary seems wierd to me.
Rich (as an individual): agree with Justin.
Sanjay in chat: thanks @darrel for prototyping for binary vs string structure field. i do not have strong opinion on this as far as while debugging and searching logs while doing root cause analysis.

To be confirmed (sf-string) on the list. Have another draft, then go to WGLC by end of April.

WG to think about it's role and talk about it on the list. Deprecation header compared to a general "lifecycle" concept is an example.

Proposed WG Documents

Maybe drop register-user from draft, does not seem to be used. Maybe change logout to something more descriptive
MNot: I raised the name-change issue. Link relations are semantic or functional. I support adoption, especially as I am the designated expert for link relations.

Hans: Do I see this once when I connect to the site, or each time?
Evert: The answer depends on what you're doing, probably. For example, public browsing compared to adding a new document. I would like browser to support logout, common chrome for logout-from-site
Ian: Logout could also be useful for password managers. I didn't see the idea of multiple headers, such as signon or single-sign-one
Evert: Link headers can have "titles" which could be used to distinguish.
Ian: Should doc be descriptive about multiple uses? Editorial note: yes
Darrel: did you have requests for a link relation to get an API key?
Evert: I think it exists in the OAuth2 world, and that might be the place for that.
Kenichi: sorry, missed the question, work interruption
Evert: answer missed.
MNot: To get most use out of link-relation need to document what the action should do. Could be all in the link-relation spec, or in the applications that use that. Seems like this is in the middle, and we can resolve during WG discussions.

Strong consensus to adopt; to be confirmed on the list.
If adopted we need to tell SEC area that we're working on this, for their review/input.

Discussions/Any Other Business

No time.