[07:03] Martin Sarabura (PTC) asked for a victim, I choose... David Honey (Persistent/IBM)

[07:03] David Honey (Persistent/IBM): David is scribe

[07:04] Martin Sarabura (PTC):

[07:05] David Honey (Persistent/IBM): No comments/objections to minutes.

[07:06] David Honey (Persistent/IBM):

[07:07] David Honey (Persistent/IBM): List of attendees: David Honey (Persistent/IBM), Jean-Luc Johnson (Airbus), Jim Amsden (IBM), Martin Sarabura (PTC), Nick Crossley (IBM)

[07:10] David Honey (Persistent/IBM): Prior to proposal, a change of access control for a collection of work items required a change for each work item.

[07:11] David Honey (Persistent/IBM): Proposal would allow work items to reference an intermediate object that delegated to access control provider. The change would require a change to the intermediate object and not each work item.

[07:14] David Honey (Persistent/IBM): Example: 1000 work items point to a real access context.

[07:14] David Honey (Persistent/IBM): Modify the access context to be a delegated one and point to a real one that implemented the changes.

[07:15] David Honey (Persistent/IBM): Can a delegated access context reference another delegated context.

[07:16] David Honey (Persistent/IBM): Proposal is to treat it like an HTTP redirect.

[07:16] David Honey (Persistent/IBM): How to handle redirect loops?

[07:17] David Honey (Persistent/IBM): recommends max of 5 redirections.

[07:19] David Honey (Persistent/IBM): Should we require that a delegated access context omit other properties?

[07:22] David Honey (Persistent/IBM): Nick: Spec cannot mandate a TRS client do the right thing with access contexts.

[07:33] David Honey (Persistent/IBM): Spec currently does not define how a client evaluates an access context. An indexer can discover all the access contexts for index resources and allow an admin to define access rights for each user/team etc.

[07:33] David Honey (Persistent/IBM): Earlier discussions could not agree on a way for a data provider to describe users as members of access contexts. So was omitted from spec.

[07:36] David Honey (Persistent/IBM): Embedding name of a team in a URI of an access context is often a poor choice. We should change our example to avoid that.

[07:37] David Honey (Persistent/IBM): Nick: Action item to update example.

[07:38] David Honey (Persistent/IBM): Nick: Action item, update proposal to limit delegated redirects to 5 as per

[07:39] Jim Amsden (IBM): - [ ] Proposal: Add a new property acc:type=acc:delegated to identify that the accessContext should be read from another resource, using the acc:accessContext value

[07:40] Jim Amsden (IBM): +1

[07:40] David Honey (Persistent/IBM): Vote

[07:40] Martin Sarabura (PTC): +1

[07:40] David Honey (Persistent/IBM): +1

[07:40] Nick Crossley (IBM): +1

[07:40] Jean-Luc Johnson (Airbus): +1

[07:40] David Honey (Persistent/IBM): Carried

[07:43] David Honey (Persistent/IBM): Jim: Would like to see a draft spec available for public review in a month's time.

[07:49] David Honey (Persistent/IBM): David: Should spec be closer aligned to LD-Patch?

[07:49] David Honey (Persistent/IBM): Jim: Have to leave it as is for compatibility with existing implementations.

[07:51] David Honey (Persistent/IBM):

[07:59] David Honey (Persistent/IBM): Cannot mandate inclusion of extra data.

[08:00] David Honey (Persistent/IBM): Action item: David to update proposal to describe cooperative producer+client.

[08:00] David Honey (Persistent/IBM): Meeting adjourned

