openid / openid/fapi

FAPI + FedCM

Open
#677 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

migrated-from-bitbucket priority: major type: bug
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by josephheenan (Joseph Heenan) on 2024-04-12

There is an effort going on at W3C to define a new browser API for iDPs to provide identity information: https://fedidcg.github.io/FedCM/

There’s two things here that I think are relevant to the FAPI working group:

  1. It is likely that at some point Browsers will break OAuth2 flows when they block the use of link decoration user tracking, and FedCM is the fix for this
  2. The FedCM API provides some potential advantages, like we may be able to use it such that the Browser (or the OS in a native app RP) is able to display a list of banks the user has previously logged into, giving the user an easier way to select a bank than the current nascar issue of 40+ UK banks and 100+ Brazil banks.

There are some slides from OSW with background on FedCM here: https://tcslides.link/OSW24-FedCM101

I think the main thing here is to raise the profile of this work within the FAPI working group. We don’t think FedCM as it is defined/implemented today quite works for the OpenBanking/FAPI type use cases, but from discussions at OAuth Security Workshop there is definitely the possibility to make some changes so it does work. One helpful thing might be if banks or fintechs would join and participate in https://www.w3.org/community/fed-id/


Bitbucket status: open

Bitbucket origin: issue 689

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the FedCM specification and the OSW FedCM101 slides linked in the issue, then review the W3C FedID Community Group referenced there. Compare the current FedCM design with Open Banking and FAPI use cases and identify what changes or working-group action would be needed. Done means producing a concrete proposal or discussion outcome for the FAPI working group.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.