2025-12-10 Commonalities Break Out Session - Token Refresh

2025-12-10 Commonalities Break Out Session - Token Refresh

 

Community Attendees:

@Jan Friman @Rafal Artych @ABOUCHI, Aziz @Murat Karabulut @Patrice Conil

Community Attendees: @pedro.diezgarcia@telefonica.com @Surajj Jaggernath Marcelo Nahum, Philippe Perrault

 

 

LF Staff:

 

Review of Action Items and Minutes from previous meetings

2025-12-03 Commonalities Break Out Session - Token Refresh

Agenda

The project's Antitrust Policy is linked from the LF and project websites. The policy is important when multiple companies, including potential industry competitors, are participating in meetings. Please review it, and if you have any questions, please contact your company’s legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.

 

-Continue Question/Discussion, Can it be an excepted solution in Camara that we require an authorization on the client side to achieve a secure solution?

-Continue Question/Discussion. Can we have an architecture that does not require a authorization server on the client (Application) side?

-Continue the discussion around Axels proposal,

Minutes

Discussion on auth server on client side (API Consumer side)

Pedro : It requires that we fully document the flow and have instructions for how the client side needs to be set up to generate tokens. not a problem but it generates more things to be in place.

Philippe : Advantage that it follow standards and also achieves best security.

Philippe : Current solution Resource server need to produce a token, this is a issue. It also not possible to refresh the token.

Pedro: In current solution the token from the API consumer does not require a full Authorization server.

Marcelo: Best would be to support both variants. It can be handled by only having one API and the parameters controls the authorization method.

Patrice: The sink credentials can be controlled by parameter from API consumer.

Marcelo to update the current sequences diagram to reflect the proposal that authorization method for the sink credential can be selected by the invoker of the API (client).

Sequence diagram will be converted to mermaid format and is planned to be reviewed at next meeitng 17/12

Rafal: Note https://github.com/camaraproject/Commonalities/issues/565

Action Points

-Extend the invitation to also include ICM members (@Jan Friman ) (Done)

-Extend the meeting series as a backup if we do not finalize (@Jan Friman ) (Done)

-Marcelo to document the new proposal in the Issue token refresh not possible on Event subscriptions · Issue #461 · camaraproject/Commonalities (In progress, planned for 17/12)

 

Next Meeting

 

Wednesday 17/12 13.00 UTC, 14.00 CET