Re: Add "oauth-authorization-resource" attribute?

"Kennedy, Smith \(Wireless & IPP Standards\) via ipp" <[email protected]>
Newsgroups gmane.ietf.ipp
Message-ID <[email protected]>
That sounds right - I couldn't remember how this played out and it doesn't seem to be covered in the wiki page.

However, I'm worried about that conclusion. If we advise that the Client supplies the "printer-uri" value as the resource identifier, wouldn't this mean that the Authentication Service needs to know the printer's current URI? That could be in the .local domain which isn't really any more useful or verifiable than a printer-uuid value. (Obviously how the printer and Authentication Service talk to one another is outside our scope of concern but that would affect whether the printer could register its URI with the Authentication Service.)

It seems like we could define the attribute but then provide guidance for how best to use it?

Smith



> On Nov 7, 2022, at 10:13 AM, Michael Sweet <[email protected]> wrote:
> 
> CAUTION: External Email
> 
> From: Michael Sweet <[email protected]>
> Subject: Re: [IPP] Add "oauth-authorization-resource" attribute?
> Date: November 7, 2022 at 10:13:17 AM MST
> To: "Kennedy, Smith (Wireless & IPP Standards)" <[email protected]>, PWG IPP Workgroup <[email protected]>
> 
> 
> Smith,
> 
> I thought we had resolved this a couple IPP concalls ago - basically, "resource" for token exchange is explicitly the URI you are using to talk to the Printer (printer-uri) or System (system-uri) and not a self-advertised and unverifiable value (printer/system-uuid) provided by the Printer/System.
> 
> 
>> On Nov 7, 2022, at 11:17 AM, Kennedy, Smith (Wireless & IPP Standards) via ipp <[email protected]> wrote:
>> 
>> Hi there,
>> 
>> I had intended to mention earlier, but in the discussion of OAuth 2.0 and IPP, it would be useful to Clients if the Printer indicated the "resource" parameter for the Token Exchange in step 34 of ipp-authentication-6-http-oauth2.pdf. Otherwise one deployment will want the value to be "printer-uuid" while another will want it to be "printer-uri" and universal clients will find it challenging to know what to use in what context.
>> 
>> Thoughts?
>> 
>> Smith
>> 
>> /**
>>    Smith Kennedy
>>    HP Inc.
>> */
>> 
>> _______________________________________________
>> ipp mailing list
>> [email protected]
>> https://www.pwg.org/mailman/listinfo/ipp
> 
> ________________________
> Michael Sweet
> 
> 
>

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEX4TM/E2Pr7lTZzy2qskbKLDW1N0FAmNpwusACgkQqskbKLDW
1N0pfxAAg5fjugiVlNuJo1Wfb8QgRr/Ib6g1TmIrcKvNNzPczlOpY98Mx6XCMByb
+Q480LTyiLT8tmVGyZpKLrV5Py2Ikxja1RcwJlsKhJ5oVajDh+M22f+Et8kiHP6l
btoLSuYxeOu1lq+6jLabz8tL1u/oQYXkQEXbj00GhFsjjEDL2rHSzJJNiwjjK9Gy
Fu1Pf3FV83FVc+B7GhPr1T4+1JutwhXVHEyfJfwk4iFNVRRM6cN/ANhF0KM8Eenn
DC1tBWRUdnwxW7HlGL1WibKoR+3jY+hjX4K2i5JG8QJV9WK/LKgmRWTlaLmFMV5a
IAZORii3CqLXi8zH/th7yCCPcRk/W2osJ93H1FnlwbGMI6FFGaXraLKkkhnnUXVb
VKPF75lLuksdsgWj/v45NYPFBF/FEgEiqhSblHsBuRT+GeKRlCTqG3yomoWy01vP
8/u6qitNq15WWfdbYJFmNDq6MDQXbd53NaJBByXKwtz9jbEabdPACOWu49jH2bwz
xC15D7laKar897MkeAhhW4T4zMk7axyUCpICh/lLsO8atK7b269evLfmMe4mVFDk
reyUaJxvZ50pEgaxLVoGO5c9ut1s0JfjfOro653NeOSt32Vx/u7nvaNNhviSNnVk
/Z8T5DeOXKunjTkw5HQMhgkfJIYpVGH32JDO1ThA3Lrx/40q4SI=
=CVCR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.