Re: Secdir last call review of draft-wilde-service-link-rel-06

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



hello.

thanks, stefan, for the review!

On 2018-11-20 11:42, Stefan Santesson wrote:
Even though this document is quite repetitive when describing its fundamental
concepts, I still had a problem figuring out whether the link relations defined
are applicable to any web resource, or just to "web services" in the context of
"service provided to another service".

in theory they apply to any web resource, but in practice descriptions and documentation in most cases will only be published for sets of resources, which this draft calls "web services". i myself am not a huge fan of this terminology, but it seems to be what most people are using.

I have no issues with the fundamental concept, but the document lacks security
considerations. The content of the section is "..." indicating that something
eventually is intended to go here, but has not yet been written. If there are
absolutely no security considerations, then the section should say so.

I do however think that there are some useful security considerations to
document. At least it may be useful to have a small discussion to consider what
information about a service that is helpful to a user, and which could be used
by an attacker, and find a good balance.

thanks for this suggestion. i have added this at https://github.com/dret/I-D/commit/3f065e662ccd66419c92246a2bba9bd8c5127ade, which adds security considerations.

As a nit I would suggest shortening some of the fundamental description in the
early introduction that is being repeated in the document. The document is
rather short and therefore does not benefit from saying the same things many
times.

i agree that there are repetitions. they are intentional, as the goal has been to make the individual sections as self-contained as possible, so that users looking for the definitions of the individual link relations can look them up and just read the individual definitions.

i think with these changes in the draft i have addressed the comments in this review. i have posted a new version of the draft that includes the changes mentioned here.

https://tools.ietf.org/html/draft-wilde-service-link-rel-07

thanks again and kind regards,

dret.

--
erik wilde | mailto:erik.wilde@xxxxxxxx |
           | http://dret.net/netdret    |
           | http://twitter.com/dret    |




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux