Hi Farazath,

Same here! Congratulations!

I agree with Eve. However, bear in mind that in some situations the RS should not even know which client is accessing the resource (the RS only has to know that a client CAN access this resource).

Cheers, Maciek

On 1 September 2015 at 15:43, Eve Maler <eve@xmlgrrl.com> wrote:
Hi Farazath— BTW, congratulations on completing your GSoC project!

Officially, the RS outsources all aspects of protection to the AS, so it doesn’t “recognize” clients in any in-band UMA way. E.g., it doesn’t see their client ID.

However, it’s free to use any contextual methods that it wants for observing and acting on requests for access. In fact, hmmm. Given the last couple of tweaks we just made to the specs in V1.0.1, where it’s not just “403 recommended and you’re on your own for any other status codes”, but “the RS can produce any status codes it wants as long as it uses the UMA header when it’s doing UMA”, you could theoretically add “preprocessing” and “postprocessing” trust elevation flows that are RS-specific.

(The user experience might get more and more horrible, though, depending on what impact it has on the requesting party. That’s for your authentication strategy to decide.)


On 31 Aug 2015, at 3:12 AM, Farazath Ahamed <mefarazath@gmail.com> wrote:


First of all thanks everyone for helping me out in this mailing list answering my questions that helped me a lot in getting through my GSoC. However, I am yet to complete my implementation. Therefore i will keep on pestering you with questions :)

Getting to the question,
We use the PAT to register permissions using the Permission Registration endpoint of the Protection API, do we have a standard way of associating the client who requests for access from the UMA protected resource server?

A.Farasath Ahamed
Undergraduate  | Department of Computer Science and Engineering,University of Moratuwa
Article Writer | MoraSpirit
WG-UMA mailing list

Eve Maler | cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl | Calendar: xmlgrrl@gmail.com

WG-UMA mailing list

Maciej Machulak
email: maciej.machulak@gmail.com
mobile: +44 7999 606 767 (UK)
mobile: +48 602 45 31 66 (PL)