#social 2016-03-29
2016-03-29 UTC
bblfish joined the channel
Arnaud1 joined the channel
KevinMarks, jasnell and jasnell_ joined the channel
#
Loqi Aaronpk made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97967&oldid=97966

bblfish, KevinMarks and jaywink joined the channel
#
Loqi Rhiaro made 1 edit to [[Socialwg/2016-03-16-minutes]] https://www.w3.org/wiki/index.php?diff=97968&oldid=97786

tsyesika joined the channel
#
Loqi Rhiaro made 3 edits to [[Socialwg/2016-03-17-minutes]] https://www.w3.org/wiki/index.php?diff=97972&oldid=0

#
Loqi Rhiaro made 2 edits to [[Socialwg/2016-03-16-minutes]] https://www.w3.org/wiki/index.php?diff=97973&oldid=97968

#
Loqi Rhiaro made 1 edit to [[Socialwg/2016-03-16-minutes]] https://www.w3.org/wiki/index.php?diff=97975&oldid=97973

#
Loqi Rhiaro made 1 edit to [[Socialwg/2016-03-17-minutes]] https://www.w3.org/wiki/index.php?diff=97974&oldid=97972

KevinMarks joined the channel
#
Loqi Rhiaro made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97976&oldid=97967

bblfish, prtksxna and jaywink joined the channel
#
Loqi Aaronpk made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97977&oldid=97976

tantek joined the channel
bblfish joined the channel
annbass joined the channel
#
cwebber2 if you're in the area, you're welcome to come: https://stripe.com/events/oss-meetup-march-2016

#
ben_thatmustbeme not at all, i'm pretty sure the topic got cleared when the irc server went down a few days back

#
ben_thatmustbeme i was getting constant attempts to reconnect

#
ben_thatmustbeme the afternoon of the 25th is when i'm seeing it started

bblfish and eprodrom joined the channel
#
eprodrom Hello all
#
ben_thatmustbeme hey eprodrom

#
Loqi Benthatmustbeme made 1 edit to [[Socialwg]] https://www.w3.org/wiki/index.php?diff=97978&oldid=97965

RRSAgent joined the channel
#
RRSAgent logging to http://www.w3.org/2016/03/29-social-irc

Zakim joined the channel
#
ben_thatmustbeme present+

#
ben_thatmustbeme we only have 5 people on the phone right now

#
eprodrom sorry, just joining
#
eprodrom present+
#
eprodrom scribe?
#
ben_thatmustbeme i'll scribe

#
ben_thatmustbeme scribenick: ben_thatmustbeme

#
ben_thatmustbeme Scribe: Ben Roberts

#
ben_thatmustbeme Chair Evan Prodrom

eprodrom joined the channel
#
ben_thatmustbeme eprodrom: lets get started, we have a few minutes to review

#
annbass I really appreciate Amy's summary notes: http://rhiaro.co.uk/2016/03/socialwg5-summary
#
ben_thatmustbeme TOPIC: approval of minutes

#
eprodrom +1
#
ben_thatmustbeme eprodrom: this is a little bit of catch up, but from 3 weeks ago. +1's

#
ben_thatmustbeme eprodrom: without any objections

Arnaud1 joined the channel
#
eprodrom +1
#
ben_thatmustbeme eprodrom: as annbass mentioned in IRC, rhiaro did a very nice summary of minutes from f2f

#
ben_thatmustbeme grr

#
ben_thatmustbeme RESOLVED: approve https://www.w3.org/wiki/Socialwg/2016-03-08-minutes

#
ben_thatmustbeme eprodrom: i have only given a slight look but they look ok to me. Would anyone like to defer to next week?

#
ben_thatmustbeme .... if not we'll just call this resolved

#
ben_thatmustbeme RESOLVED: approve the minutes for 3/16 and 3/17

#
Loqi Cwebber2 made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97979&oldid=97977

#
ben_thatmustbeme eprodrom: i think this covers all our administrative issues, but its worth noting that we set up a schedule for face to faces for the next 9 months

#
ben_thatmustbeme ... our plan is to have them in June, Sept, and i think November

#
tantek see https://www.w3.org/wiki/Socialwg#Future_Meetings for next f2fs

#
ben_thatmustbeme ... if you were not at the F2F you should check that to see that they fit your schedule

#
ben_thatmustbeme ... see link in IRC, thank you tantek

#
tantek in particular please RSVP ASAP to https://www.w3.org/wiki/Socialwg/2016-06-07

#
ben_thatmustbeme ... we have Portland in June, Lisbon in September

#
ben_thatmustbeme TOPIC: AS2 status

#
tantek (only 7 RSVPs so far https://www.w3.org/wiki/Socialwg/2016-06-07#Participation everyone should say if they can go or not)

#
ben_thatmustbeme eprodrom: maybe i can, as unfortunately both chair and editor today, you'll hear me a lot

#
ben_thatmustbeme ... where we got at the F2F is that a couple of the big items for AS2 we got worked out

#
ben_thatmustbeme ... conformance clause and ?

#
ben_thatmustbeme ... test suite

#
ben_thatmustbeme ... unfortunately by the time we got to Boston, we had a number of issues that arose

#
ben_thatmustbeme ... our current list is 13 issues, we addressed a number of these at f2f

#
ben_thatmustbeme ... a majority of the ones tha required input from the group we resolved

#
ben_thatmustbeme ... unfortunately some of them, the main editor who was not participating in boston, -1'd them and so we may have to resolve some of those again

#
eprodrom jasnell?
#
ben_thatmustbeme ... it comes down to an issue of an editor is opposed to a group resolution so i suggest we re-open some of these issues and try to resolve them again

#
ben_thatmustbeme ... i think james is not on the call

#
eprodrom ack tantek
#
ben_thatmustbeme ... I think that we pushed these forward while james wasn't there, he pushed back on them, and I'd like to come to a resolution with him on these, if we can't we'll have to figure out the proceedure

#
KevinMarks present+

#
ben_thatmustbeme tantek: for w3c, we do try to get consensus, we try to get the dissenter to explain their position. Its possible that person has found a flaw that no one else sees

#
ben_thatmustbeme ... when they present that, often others see the issue and change their vote

#
ben_thatmustbeme ... if after the explanation, no one else is still opposed, after that it becomes an issue for the chairs and a chair can declare consensus and just note the official objection

#
ben_thatmustbeme ... but to do that we need james to call in

#
ben_thatmustbeme ... the next step would be to get james to commit to a specific telcon where he can call in and give his explanation, we really need him to explain it himself, since there is usually back and forth

#
ben_thatmustbeme ... if he is not on the call, that falls to the chair, to decide how long to wait and if it runs too long we have to make a judgement call on that

Arnaud1 joined the channel
#
ben_thatmustbeme ... maybe we could action you evan to contact james

#
Loqi Tantekelik made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97980&oldid=97979

#
ben_thatmustbeme eprodrom: that sounds good, i'll take it as an action on myself to get in contact with james and try to resolve these

#
ben_thatmustbeme ... if we can get these resolutions done the rest is just editorial issues

#
ben_thatmustbeme tantek: and remind james that these are blocking CR for us, so the sooner he can get them done, the better

#
ben_thatmustbeme eprodrom: hopefully we can get james in for next weeks telcon

#
ben_thatmustbeme ... hopefully we can get some resolutions online

#
ben_thatmustbeme tantek: great

#
ben_thatmustbeme TOPIC: status of as2 test suite

#
ben_thatmustbeme i think this is a left-over from before, as we haven't had much movement in the past two weeks

#
eprodrom https://as2.rocks/
#
ben_thatmustbeme eprodrom: i gave a demo at f2f, there is still quite a bit of work to be done as far as making it look better and such, but it is at a usable point for people to test their as2 documents

#
ben_thatmustbeme ... at the f2f we felt this met our needs for our test suite. I think there is some additional work that is going to go on there. There are a few open issues that i will link in IRC, but thats going to be an ongoing developement effort

#
ben_thatmustbeme ... any questions about validator or test suite?

#
ben_thatmustbeme ... hearing none, lets move on

#
ben_thatmustbeme TOPIC: document status for our various documents

#
ben_thatmustbeme eprodrom: we've already discussed as2 lets start discussing other documents

#
ben_thatmustbeme ... i'm not sure it makes sense to just highlight changes in the last week

#
ben_thatmustbeme ... i note that aaronpk has added a seperate discussion item around webmention

#
tantek just updated https://www.w3.org/wiki/Socialwg/2016-03-29#Discussion_Items to note new Webmention WD today

#
eprodrom ack aaronpk
#
ben_thatmustbeme ... for any of the OTHER documents, have we had any significant developements since 2 weeks ago

#
ben_thatmustbeme aaronpk: with micropub i don't have a new draft published, but i do have an editors draft with the combined micropub and activitypub syntax. I'd say it is very much in progress right now

#
ben_thatmustbeme eprodrom: excellent and you are coordinating with amy chris and jessica about that?

#
ben_thatmustbeme ... do you need anything else from us?

#
ben_thatmustbeme aaronpk: no

#
ben_thatmustbeme eprodrom: anything for activitypub?

#
ben_thatmustbeme tsyesika: we have done some work, but we have been busy and have not had a chance to close all the issues YET

#
ben_thatmustbeme eprodrom: lets move on to webmentions

#
ben_thatmustbeme aaronpk: i published a new draft of webmention with things we disucssed (links new version)

#
ben_thatmustbeme ... its not a huge change but there is a bunch of language and phrasing clarification, some of that thanks to annbass.

#
ben_thatmustbeme ... there is a new section about sending webmentions when you edit posts

#
ben_thatmustbeme ... there is a new section on conformance criteria

#
ben_thatmustbeme ... and the note about not sending to localhost

#
ben_thatmustbeme ... and the note about turning field names in to URIs

#
ben_thatmustbeme ... those are the summary of changes in this draft

#
ben_thatmustbeme eprodrom: and this is a live WD, FANTASTIC

#
ben_thatmustbeme ... thats a good step forward for us

#
ben_thatmustbeme ... are there other issue around WM we need to discuss

#
ben_thatmustbeme aaronpk: yes, i used our new labels and went through all old issues and added appropriate labels to them

#
ben_thatmustbeme ... in doing that there were a couple that were marked for review by the group

#
ben_thatmustbeme ... i wanted to get some group feedback on this

#
Loqi Tantekelik made 1 edit to [[Socialwg/2016-03-29]] https://www.w3.org/wiki/index.php?diff=97981&oldid=97980

#
ben_thatmustbeme ... issue 20 is a challenging one, we talked about this at F2F, said its similar to how HTML loads external resources, and its actually slightly different in that is does POST not just perform GET

#
ben_thatmustbeme ... i am not sure how to word the security warning

#
ben_thatmustbeme ... its really an issue about systems outside of webmention

#
ben_thatmustbeme ... anyone have any suggestions?

#
ben_thatmustbeme tantek: i just read the updates on the issue, and in terms of the post vs get. There is one more place in HTML you can get similar data. That is Forms. its possible to POST cross site that way

#
ben_thatmustbeme ... and presumably HTML has to say something about that

#
ben_thatmustbeme ... we could just reference HTML and say that it follows HTMLs security concerns

#
ben_thatmustbeme aaronpk: okay, i can take a look at that and hope i find something there

#
KevinMarks is xmlhttprequest relevant too?

#
ben_thatmustbeme eprodrom: yeah, i'm just wondering if we can make this more general as tantek suggests. I don't think describing each and every possibility is worth it. but noting that a sender can get anyone to post to

#
ben_thatmustbeme ... something like "this is an URL that someone is giving to you, and you can't fully trust that"

#
ben_thatmustbeme tantek: its acting just like a browser would when doing a cross-site form POST

#
ben_thatmustbeme ... and maybe we just say we should follow the same method browsers use

#
ben_thatmustbeme ... at least implementers can look at that as a starting point

#
ben_thatmustbeme eprodrom: it would be nice to find some common language and point to that rather than having to rewrite it all in webmention

#
ben_thatmustbeme tantek: exactly, thats why i say point to HTML unless someone can come up with some way that its actually different

#
ben_thatmustbeme eprodrom: aaronpk, with webmention, are there other issues?

#
ben_thatmustbeme aaronpk: one more

#
ben_thatmustbeme ... #14, the thread is long but the end of it describes it, basically webmention only requires that source and target exist and doesn't use anything else. Right now there is no access token or cookies or anything

#
ben_thatmustbeme ... there is a concern that if a webmention request accidently does have credentials in it, someone might be committed to something they might not be aware of

#
ben_thatmustbeme ... however i don't want to disallow tokens, as it will be important for private webmentions

#
ben_thatmustbeme tantek: this happens in CSS a lot, there is some potentially advanced feature that we are not ready for, but we want to allow for, but its to put in a note saying this spec does not define any handling for webmentions that may have additional headers such as authentication headers such as ... etc

deiu joined the channel
#
ben_thatmustbeme ... by specifically saying that the spec doesn't specify any special handling, you are basically saying If you implement with them, thats fine

#
ben_thatmustbeme ... that leave the possibility open

#
ben_thatmustbeme ... just say "this specification does not define ....."

#
ben_thatmustbeme aaronpk: will that handle the origianl issue? is sandro on the call since he commented on it before.

#
ben_thatmustbeme eprodrom: i'm not sure i understand, leaving authentication open, or unspecified, i'm not sure i understand henry's point here, can you break that down?

#
ben_thatmustbeme aaronpk: i can try. He is saying that there is a risk of (as source and target are not uris) the target page could use query parameters in the webmention url you could send any specific values you want

#
ben_thatmustbeme eprodrom: so he wants to disallow authentication why?

#
ben_thatmustbeme aaronpk: no its that it could generate a generic post to some endpoint that could do some action

#
ben_thatmustbeme eprodrom: ahh, i see, if you are logged in, you browser could send your cookies etc

#
ben_thatmustbeme ... so if i provide the webmention URL that could be set to "friend someone on facebook" etc

#
ben_thatmustbeme ... i've always thought of webmention for server to server only

#
eprodrom ack tantek
#
ben_thatmustbeme aaronpk: me too, but its possible that the server could include cookies

#
ben_thatmustbeme tantek: there is also a growing practice by many to include a form on their site that says "paste your URL here to send me a webmention"

#
ben_thatmustbeme ... to allow people who don't support webmention yet to still send a webmention. thats the one existing scenario i know of where there is a browser sending a webmention

#
ben_thatmustbeme ... so maybe thats worth mentioning that its only to the site its on

#
ben_thatmustbeme ... thats again something that seems HTML level, and not specific for webmention

#
ben_thatmustbeme aaronpk: thats exactly html, this is a standard XSS issue. so maybe the solution is the same as issue 20 which is about preventing these cross site posts

#
ben_thatmustbeme eprodrom: i think thats probably best, saying there is a possibility of XSS here and take necerssary precautions to avoid that

#
ben_thatmustbeme ... i realize the issues tend to be pretty esoteric, but thats probably a good sign that we covered the low hanging fruit

#
ben_thatmustbeme ... thats the end of the agenda for today, any other discussion items for today?

#
ben_thatmustbeme *crickets*

#
ben_thatmustbeme ... i can get into tracker but i don't think there is anything new there

#
eprodrom ack tantek
#
ben_thatmustbeme hearing nothing, we can... oh, tantek?

#
eprodrom Arnaud: ?
#
ben_thatmustbeme tantek: i thought i saw arnaud on the call maybe we can get it resolved now who is chairing next week?

#
ben_thatmustbeme Arnaud: yes, i can do it next week

#
eprodrom Thanks for scribing, ben_thatmustbeme
#
ben_thatmustbeme trackbot, end meeting

#
eprodrom ben_thatmustbeme++
#
RRSAgent I have made the request to generate http://www.w3.org/2016/03/29-social-minutes.html trackbot

#
ben_thatmustbeme Zakim, bye

#
ben_thatmustbeme Comcast--

#
ben_thatmustbeme LOL

bblfish joined the channel
#
Loqi Benthatmustbeme made 2 edits to [[Socialwg/2016-03-29-minutes]] https://www.w3.org/wiki/index.php?diff=97990&oldid=0

jaywink_ and KevinMarks joined the channel
#
Loqi Benthatmustbeme made 3 edits to [[Socialwg]] https://www.w3.org/wiki/index.php?diff=97995&oldid=97978

#
Loqi Benthatmustbeme made 1 edit to [[Socialwg/2016-03-29-minutes]] https://www.w3.org/wiki/index.php?diff=97993&oldid=97990

bblfish_ joined the channel
#
cwebber2 also I didn't have access to a graphics tablet. Usually I do some release art digitally: http://mediagoblin.org/news/mediagoblin-0.5.0-goblin-force.html

jasnell and bblfish joined the channel
#
tantek rhiaro++ great summary of the f2f Amy! http://rhiaro.co.uk/2016/03/socialwg5-summary

bblfish_ and jasnell joined the channel