Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Incoroporate Jesús text about offline

...

Attendees (Please add or remove yourself)

CompaniesAttendees
Deutsche Telekom AGHerbert Damker, Axel Nennker, Shilpa Padgaonkar
EricssonElisabeth Mueller, Jan Friman
GapaskRajesh Murthy
GSMAMark Cornall, Toyeeb Rehman, Tom van Pelt
KPNHuub Appelboom
NokiaTanja De Groot, Gaurav Agarwal
OIDFBjorn Hjelm (OIDF), Joseph Heenan
ShabodiKevin Howe-Patterson
SingtelFoo Ming Hui
Spry Fox NetworksRamesh Shanmugasundaram, Parichaya Shrivastava
T-Mobile PLDawid Wroblewski, Artych, Rafał
T-Mobile USKarabulut, Murat
TelefónicaJesús Peña García-Oliva, Diego Gonzalez Martínez, Guido García,
Juan Fabio García, Pedro Ballesteros, David Vallejo,
Juan Antonio Hernando, Diego Yonadi
VodafoneSönke Peters, Sachin Kumar
VodacomSurajj Jaggernath

Izahir Clemencia Image Modified

Camara People

Participants

...

Discussion about offline-access and Refresh Token PR

Axel provided text for Offline-access for authorization code flow that Jesús said matches the GSMA text, but the CIBA related text for offline-access is TBD. On the one hand, Jesús Peña García-Oliva  said that he supports (and Telefónica) that the final text we end up agreeing on regarding offline access definitely needs to be included in the CAMARA OIDC profile. But specifically regarding the refresh_token/offline_access flows included in CAMARA-API-access-and-user-consent.md in that PR, the working group should make a decision if we want to merge them eventually or if the PR should be closed considering only the offline access section of the profile. The original request was to move the information from GSMA to CAMARA.

On the other hand, regarding the proposed offline access text for the OIDC profile in the PR, Jesús Peña García-Oliva  said that he is fine with this text, except for the rules copied from the OIDC standard. In the case of CAMARA, authorization code is not the only flow to support. For example, offline_access must also be allowed for the CIBA flow. And I also mentioned that there was no requirement on the prompt value or application type to use the offline_access scope to request a refresh token to cover Opengateway off-net scenarios to access CAMARA service APIs.

Then Axel Nennker clarified that the proposed text was only for Auth code flow, which Jesús Peña García-Oliva  hadn't noticed before. 

Axel asked for some days to provide CIBA-related text.

...