solid / solid/data-interoperability-panel

[Ecosystem] strongly identifiable clients can also act on behalf of a user and be piloted as well

Open
#50 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Bikeshed
Stars
58
Forks
18
PR merge metrics
No merged PRs in 30d

Description

3.2. Limiting access by client application states

In the case of a strongly identifiable server-side application, the authenticated agent and the client application are the same. The client application has its own identity that can be strongly authenticated. Alice chooses which data that client application’s identity can access, in the same way that she chooses which data Bob can access.

I see it describing only one of possible cases. Strongly identifiable server-side client can just as well act on behalf of user who delegated access to it in the same way as they would do it for weakly identifiable client.

When it comes to piloting, strongly identifiable server-side client would use solid client as part of that server-side application, it can still provide custom client-server api (eg. using actor pattern) for the interface used to pilot it by the user. That means that user can pilot strongly identifiable server-side clients just as they can pilot weakly identifiable clients.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with section 3.2, “Limiting access by client application,” and read the issue’s comment thread to understand the unresolved distinction between strongly identifiable clients and delegated user access. Done means the specification clearly covers both client-identity access and clients acting on behalf of a user, including piloting.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.