-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Are Infosec end points in scope for Get Metrics API? #299
Comments
Hi @xchen-ibm I don't think I've seen any detail about your question 1, but something similar to your question 2 was asked in issue 276 and also relates to some discussion in issue 274. |
Actually, related to questions 1 and 2, there was an unanswered comment on issue 147. |
@CDR-API-Stream : Clarification is needed on the scope of endpoints listed in the availability requirement depicted in the standards and categorisation of the Grant consent flow. As per the availability requirement specified the standards here ,
Consent/Authorisation endpoint (Listed here) -> Does not require an access token for issuing requests to Authorisation endpoint BUT requires customer inputs to yield the access token to be presented for calls like getAccounts. This conflicts with the definition for Customer-Present here which explicitly mentions Authenticated. What is the classification for Consent/Authorisation endpoint and is this flow still a part of metrics requirement? |
Hi @xchen-ibm
Yes. This was further clarified in v1.5.0 of the standards
Yes all Info Sec end points should be considered high priority. It is understood that "x-fapi-customer-ip-address" only applies to protected resource endpoints. |
Hi @jas8BEN , The references you link to are the archived 1.3.1 version of the data standards not the most up to date version:
The statement for Customer Present calls is meant to apply to (authenticated) protected resources where the customer's presence is represented by the
This was clarified in v1.5.0 of the standards. InfoSec end points are to be treated as High Priority. |
This issue has been answered. Accordingly, the issue is closed. |
Infosec end points are currently listed as part of the 'High Priority' performance tier for a customer present scenario:
Have two questions in the context of Get Metrics API:
The text was updated successfully, but these errors were encountered: