40 likes | 151 Views
Here is a list of topics raised by you all that we will touch on. Issues Raised and Implementation Questions How to use BR= bulkID – relates to HD #61 Service Request 83 – including Function Block for optional customer info (service point address, etc.)
E N D
Here is a list of topics raised by you all that we will touch on • Issues Raised and Implementation Questions • How to use BR=bulkID – relates to HD #61 • Service Request 83 – including Function Block for optional customer info (service point address, etc.) • Service Request 84 – having scope selection screen on Data Custodian Site vs 3rd Party site • Tariff Model Resource • Green Button Connect My Data Testing and Certification • Complete function block descriptions • Complete test case requirements
How to use BR=bulkID – relates to HD #61 • Application Profiles • BulkID was proposed for large sets of authorizations • One account level authorization on top of service level accounts – how to do this • Degrees of freedom we have now – can we cover • Subscription – 1 or more Usage Points • Granularity of a customer authorization • BulkID • “macro” for a large set of existing authorizations • Is there another degree needed?
Contributed by Jerry Yip • Clarification/confirmation about ESPI standard: Does ‘shared resource key’ referenced in the NAESB Ratified word doc correspond to Access Token for oAuth? • Yes: This is the access token in the new Oauth 2.0 paradigm. • Formal Submission of Application Profile for bulk (vs. batch?) use case as part of GB/GBC Conformance Testing Plan • Write up coming to test concept of BulkIDs • Question: (options to address 1 Acct to many SA issue)- Does UUID correspond to usage point (1-to-1 relationship)? Is there passing of UUIDs (as resource terms in Scope section of GBAuthorization) during authorization sequence? (how would 3rd Party know multiple usage points have been authorized via single oAuth sequence/login?)- Can multiple access tokens be issued (1 token per SA) per oAuth session? • An Authorization is one access_token • How does Third Party get to know the depth of data (how many Ups) are in the authorization • Perhaps an extension of scope string to have numUPs? • Request to consider scope selection screens at Data Custodian Portal instead of 3rd party portal (Need customer to select SAs to share – only Data Custodian has that info) – also minimizes number of redirects (?) • Customer info as optional functional block (atom feed) for authorization (sharing with 3Ps) • John suggests – prep a large multi account data set and test against a reference sw implementation and measure. SFTP and Streaming, compressed and non-compressed method and compare.