Description:
This group has been created to discuss: A RESTFul Protocol for Run-Time Integration of Workflow Process Engines
|
|
|
Consumer Registration Scalability Issues
|
| |
With the OAuth protocol, Application Consumers (AC) need to be registered at the Service Provider (SP) before starting any transactions. This is a problem for scalability. I can think of two good reasons for doing registration though: - This guarantees some kind of trust regarding the AC identity. SP... more »
|
|
Detailed Security Interaction Scenario
|
| |
I have attempted to describe the complete interaction around what has
to happen to set up a workflow that makes secure calls to other
services. This covers only the "subworkflow" which makes a call to
the weather model service and the plume calculation service.
What I have found is that a user (named Andy) can provision a workflow... more »
|
|
Step2: OpenID + OAuth
|
| |
There is actually a group that is working on extending OpenID+OAuth.
[link]
[link]
Brian Kissel at Janrain pointed it out to me. "...JanRain has been
working closely with Google, Yahoo, Plaxo and others on this approach"
Pat.
|
|
Could we leverage OpenID + OAuth and if yes, how?
|
| |
OAuth has been developed independently from OpenID (did not make the
assumption that OpenID was required).
I would like to explore what if OAuth could actually leveraged the
presence of OpenID and OpenID servers.
Here is a mixed scenario:
OAuth request comes in to a service provider (SP) over SSL from an... more »
|
|
Access Token Management
|
| |
Keith, you said
"It is EXACTLY the same precaution that you must take with passwords.
You can think of this token as a password because that is essentially
what it is (but it is for a very specific purpose so it is harder to
abuse). Any program that handles passwords today must take these
precautions."... more »
|
|
Workflows, security and delegation of authority to workflows
|
| |
Keith and I have been exchanging emails regarding the OWS-6 scenario
and the security implication to workflows.
I think that it is getting close to the time to start capturing the
issues and converge towards an acceptable architecture for
interoperability so we can get ready for our first TIE.... more »
|
|
First Draft Workcast
|
| |
I have an initial copy of the RSS-based Workcast protocol fleshed out
by Sameer Pradhan. I don't right now see how to attach a document to
this message, so I will fill figure out how to forward it by email.
Please look for it.
|
|
Workflow-casting or publishing for discovery
|
| |
I would really like to complete that section very soon.
We did a lot of work in that area during OWS-5. Phil mentioned some
shortcomings in his thesis. I would love to see that work continue.
Publishing workflows using atom feeds is important but I do not want
to fall back into a higher level RPC style of publishing operations/... more »
|
|
What is a Workflow?
|
| |
At the OGC OWS-6 Kickoff meeting in Fairfax Virginia this week, Keith
Swenson asked me a very interesting question (although I did not think
so at the time):
In YOUR Opinion, What Is A Workflow?
It does not seem like much of a question but a whole industry is
building on this.
So the question deserves an answer.... more »
|
|
|