# Meeting Notes 2024-07-02 ## Attendees 👉 Add your names here omri Gerry Gebel Phillip Messerschmidt Eve Maler David Brossard David Hyland Steve Venema Victor Lu ## Agenda - Update on permit/deny spec - Boxcarring proposal - Update the interop ## Actions - Omri will update the ToDo app - We will have to re-certify the implementations when they make their updates ## Open Issues ## Notes - Permit/deny spec is now listed on AuthZEN web page - includes latest changes from last week's discussion - interop implementations are now out of compliance - Boxcarring - What are the next steps? - Do we want boxcarring as a separate spec or part of the core spec? - There seems to be consensus to have a single spec. (Eve, Alex, David) - Omri suggests some implementations may not implement both endpoints (`/evaluation` and `/evaluations`) - Steve suggests it should be a different document - Do we need a discoverability endpoint? - We can defer for now - Alex: NGAC has discoverability features - Add verbiage in the spec to make the _boxcarring_ feature optional. - We do not want the goalposts moving during the voting period for the implementer's draft. - We'll fork the current document (implementer's draft) to add boxcarring (eventually become v1.1) - Should there be pagination in the boxcarring API? - Protect from DoS and other attacks