/* style-autolinks */
.css.css,, .descriptor.descriptor {
color: #005a9c;
font-size: inherit;
font-family: inherit;
.css::before, .property::before, .descriptor::before {
content: "‘";
.css::after, .property::after, .descriptor::after {
content: "’";
.property, .descriptor {
/* Don't wrap property and descriptor names */
white-space: nowrap;
.type { /* CSS value <type> */
font-style: italic;
pre .property::before, pre .property::after {
content: "";
[data-link-type="maybe"]::before {
content: "‘";
[data-link-type="maybe"]::after {
content: "’";
.prod [data-link-type]::before,
.prod [data-link-type]::after {
content: "";
[data-link-type=element-attr] {
font-family: Menlo, Consolas, "DejaVu Sans Mono", monospace;
font-size: .9em;
[data-link-type=element]::before { content: "<" }
[data-link-type=element]::after { content: ">" }
[data-link-type=biblio] {
white-space: pre;
/* style-counters */
body {
counter-reset: example figure issue;
.issue {
counter-increment: issue;
.issue:not(.no-marker)::before {
content: "Issue " counter(issue);
.example {
counter-increment: example;
.example:not(.no-marker)::before {
content: "Example " counter(example);
.illegal.example:not(.no-marker)::before {
content: "Invalid Example" counter(example);
figcaption {
counter-increment: figure;
figcaption:not(.no-marker)::before {
content: "Figure " counter(figure) " ";
/* style-md-lists */
/* This is a weird hack for me not yet following the commonmark spec
regarding paragraph and lists. */
[data-md] > :first-child {
margin-top: 0;
[data-md] > :last-child {
margin-bottom: 0;
/* style-selflinks */
.heading, .issue, .note, .example, li, dt {
position: relative;
a.self-link {
position: absolute;
top: 0;
left: calc(-1 * (3.5rem - 26px));
width: calc(3.5rem - 26px);
height: 2em;
text-align: center;
border: none;
transition: opacity .2s;
opacity: .5;
a.self-link:hover {
opacity: 1;
.heading > a.self-link {
font-size: 83%;
li > a.self-link {
left: calc(-1 * (3.5rem - 26px) - 2em);
dfn > a.self-link {
top: auto;
left: auto;
opacity: 0;
width: 1.5em;
height: 1.5em;
background: gray;
color: white;
font-style: normal;
transition: opacity .2s, background-color .2s, color .2s;
dfn:hover > a.self-link {
opacity: 1;
dfn > a.self-link:hover {
color: black;
a.self-link::before { content: "¶"; }
.heading > a.self-link::before { content: "§"; }
dfn > a.self-link::before { content: "#"; }</style>
<body class="h-entry">
<div class="head">
<p data-fill-with="logo"></p>
<h1 class="p-name no-ref" id="title">Solid Use Cases and Requirements</h1>
<h2 class="no-num no-toc no-ref heading settled" id="subtitle"><span class="content">Editor’s Draft, <time class="dt-updated" datetime="2020-05-18">18 May 2020</time></span></h2>
<div data-fill-with="spec-metadata">
<dt>This version:
<dd><a class="u-url" href=""></a>
<dt>Issue Tracking:
<dd><a href="">GitHub</a>
<dd><a href="#issues-index">Inline In Spec</a>
<dt class="editor">Editor:
<dd class="editor p-author h-card vcard"><span class="p-name fn">elf Pavlik</span>
<div data-fill-with="warning"></div>
<p class="copyright" data-fill-with="copyright"><a href="" rel="license"><img alt="CC0" src=""></a> To the extent possible under law, the editors have waived all copyright
and related or neighboring rights to this work.
In addition, as of 18 May 2020,
the editors have made this specification available under the <a href="" rel="license">Open Web Foundation Agreement Version 1.0</a>,
which is available at
Parts of this work may be from another specification document. If so, those parts are instead covered by the license of that specification document. </p>
<hr title="Separator for header">
<div class="p-summary" data-fill-with="abstract">
<h2 class="no-num no-toc no-ref heading settled" id="abstract"><span class="content">Abstract</span></h2>
<p>Use Cases and Requirements for Solid ecosystem.</p>
<div data-fill-with="at-risk"></div>
<nav data-fill-with="table-of-contents" id="toc">
<h2 class="no-num no-toc no-ref" id="contents">Table of Contents</h2>
<ol class="toc" role="directory">
<li><a href="#intro"><span class="secno">1</span> <span class="content">Introduction</span></a>
<a href="#requirements"><span class="secno">2</span> <span class="content">Requirements</span></a>
<ol class="toc">
<li><a href="#the-system-is-not-abusable"><span class="secno">2.1</span> <span class="content">The system is not abusable</span></a>
<li><a href="#an-app-can-request-access-to-a-specific-resource"><span class="secno">2.2</span> <span class="content">An app can request access to a specific resource</span></a>
<li><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod"><span class="secno">2.3</span> <span class="content">An app can request access to a specific type of data without knowing the structure of resources on a Pod</span></a>
<li><a href="#access-requests-can-be-sent-when-the-resource-owner-is-not-present-to-be-approved-once-the-user-is-present"><span class="secno">2.4</span> <span class="content">Access requests can be sent when the resource owner is not present to be approved once the user is present</span></a>
<li><a href="#apps-can-request-the-ability-to-write-a-specific-type-of-data-and-will-be-told-where-it-should-write-it"><span class="secno">2.5</span> <span class="content">Apps can request the ability to write a specific type of data and will be told where it should write it</span></a>
<li><a href="#it-should-be-possible-for-an-agent-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-that-agent"><span class="secno">2.6</span> <span class="content">It should be possible for an agent to block/allow certain apps from accessing a specific resource as that agent</span></a>
<li><a href="#it-should-be-possible-for-an-agent-with-control-access-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-any-agent"><span class="secno">2.7</span> <span class="content">It should be possible for an agent with Control access to block/allow certain apps from accessing a specific resource as any agent</span></a>
<li><a href="#it-should-be-easy-to-allow-others-accessing-your-resources-to-use-apps-youre-okay-without-requiring-your-explicit-consent"><span class="secno">2.8</span> <span class="content">It should be easy to allow others accessing your resources to use apps you’re okay without requiring your explicit consent.</span></a>
<li><a href="#access-to-specific-types-of-data-should-extend-to-new-resources-that-contain-that-data"><span class="secno">2.9</span> <span class="content">Access to specific types of data should extend to new resources that contain that data</span></a>
<li><a href="#access-to-specific-types-of-data-should-not-expose-other-data-that-was-not-requested"><span class="secno">2.10</span> <span class="content">Access to specific types of data should not expose other data that was not requested</span></a>
<li><a href="#data-should-have-different-levels-of-requirements-for-users-conciousness-in-consent"><span class="secno">2.11</span> <span class="content">Data should have different levels of requirements for user’s conciousness in consent</span></a>
<li><a href="#the-authorization-data-is-easily-cachable"><span class="secno">2.12</span> <span class="content">The authorization data is easily cachable</span></a>
<li><a href="#information-about-clients-apps-to-which-users-have-granted-access-and-what-specific-access-they-have-delegated-should-not-be-made-available-to-resource-servers-that-do-not-enforce-relevant-access-restrictions-on-those-clients"><span class="secno">2.13</span> <span class="content">Information about Clients (apps) to which users have granted access and what specific access they have delegated should not be made available to Resource Servers that do not enforce relevant access restrictions on those Clients.</span></a>
<a href="#use-cases"><span class="secno">3</span> <span class="content">Use Cases</span></a>
<ol class="toc">
<li><a href="#simple-game"><span class="secno">3.1</span> <span class="content">Simple game</span></a>
<li><a href="#chat-with-friends"><span class="secno">3.2</span> <span class="content">Chat with friends</span></a>
<li><a href="#chat-with-doctor"><span class="secno">3.3</span> <span class="content">Chat with doctor</span></a>
<li><a href="#discussion-boards"><span class="secno">3.4</span> <span class="content">Discussion boards</span></a>
<li><a href="#rdf-editor"><span class="secno">3.5</span> <span class="content">RDF editor</span></a>
<li><a href="#pod-administration"><span class="secno">3.6</span> <span class="content">Pod administration</span></a>
<li><a href="#photos-viewer"><span class="secno">3.7</span> <span class="content">Photos viewer</span></a>
<li><a href="#photos-organizer"><span class="secno">3.8</span> <span class="content">Photos organizer</span></a>
<li><a href="#photos-processing"><span class="secno">3.9</span> <span class="content">Photos processing</span></a>
<li><a href="#evil-fitness-tracker"><span class="secno">3.10</span> <span class="content">Evil fitness tracker</span></a>
<li><a href="#finances-tracker"><span class="secno">3.11</span> <span class="content">Finances tracker</span></a>
<li><a href="#restaurants-tracker"><span class="secno">3.12</span> <span class="content">Restaurants tracker</span></a>
<li><a href="#blogs"><span class="secno">3.13</span> <span class="content">Blogs</span></a>
<li><a href="#custom-tls-ca"><span class="secno">3.14</span> <span class="content">Custom TLS CA</span></a>
<li><a href="#conformance"><span class="secno"></span> <span class="content"> Conformance</span></a>
<a href="#references"><span class="secno"></span> <span class="content">References</span></a>
<ol class="toc">
<li><a href="#normative"><span class="secno"></span> <span class="content">Normative References</span></a>
<li><a href="#issues-index"><span class="secno"></span> <span class="content">Issues Index</span></a>
<h2 class="heading settled" data-level="1" id="intro"><span class="secno">1. </span><span class="content">Introduction</span><a class="self-link" href="#intro"></a></h2>
<p class="issue" id="issue-c29b11aa"><a class="self-link" href="#issue-c29b11aa"></a> Needs explaination how proposals should clearly reference requirements which they satisfy. As well as requirements they do not satisfy due to some limitations.</p>
<h2 class="heading settled" data-level="2" id="requirements"><span class="secno">2. </span><span class="content">Requirements</span><a class="self-link" href="#requirements"></a></h2>
<h3 class="heading settled" data-level="2.1" id="the-system-is-not-abusable"><span class="secno">2.1. </span><span class="content">The system is not abusable</span><a class="self-link" href="#the-system-is-not-abusable"></a></h3>
<div class="assertion no-marker">
<div class="marker">Use cases</div>
<li data-md>
<p><a href="#evil-fitness-tracker">§ 3.10 Evil fitness tracker</a></p>
<h3 class="heading settled" data-level="2.2" id="an-app-can-request-access-to-a-specific-resource"><span class="secno">2.2. </span><span class="content">An app can request access to a specific resource</span><a class="self-link" href="#an-app-can-request-access-to-a-specific-resource"></a></h3>
<div class="assertion no-marker">
<div class="marker">Use cases</div>
<li data-md>
<p><a href="#simple-game">§ 3.1 Simple game</a></p>
<li data-md>
<p><a href="#rdf-editor">§ 3.5 RDF editor</a></p>
<li data-md>
<p><a href="#pod-administration">§ 3.6 Pod administration</a></p>
<h3 class="heading settled" data-level="2.3" id="an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod"><span class="secno">2.3. </span><span class="content">An app can request access to a specific type of data without knowing the structure of resources on a Pod</span><a class="self-link" href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod"></a></h3>
<div class="assertion no-marker">
<div class="marker">Use cases</div>
<li data-md>
<p><a href="#chat-with-friends">§ 3.2 Chat with friends</a></p>
<li data-md>
<p><a href="#discussion-boards">§ 3.4 Discussion boards</a></p>
<li data-md>
<p><a href="#photos-viewer">§ 3.7 Photos viewer</a></p>
<li data-md>
<p><a href="#photos-processing">§ 3.9 Photos processing</a></p>
<h3 class="heading settled" data-level="2.4" id="access-requests-can-be-sent-when-the-resource-owner-is-not-present-to-be-approved-once-the-user-is-present"><span class="secno">2.4. </span><span class="content">Access requests can be sent when the resource owner is not present to be approved once the user is present</span><a class="self-link" href="#access-requests-can-be-sent-when-the-resource-owner-is-not-present-to-be-approved-once-the-user-is-present"></a></h3>
<h3 class="heading settled" data-level="2.5" id="apps-can-request-the-ability-to-write-a-specific-type-of-data-and-will-be-told-where-it-should-write-it"><span class="secno">2.5. </span><span class="content">Apps can request the ability to write a specific type of data and will be told where it should write it</span><a class="self-link" href="#apps-can-request-the-ability-to-write-a-specific-type-of-data-and-will-be-told-where-it-should-write-it"></a></h3>
<div class="assertion no-marker">
<div class="marker">Use cases</div>
<li data-md>
<p><a href="#photos-processing">§ 3.9 Photos processing</a></p>
<h3 class="heading settled" data-level="2.6" id="it-should-be-possible-for-an-agent-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-that-agent"><span class="secno">2.6. </span><span class="content">It should be possible for an agent to block/allow certain apps from accessing a specific resource as that agent</span><a class="self-link" href="#it-should-be-possible-for-an-agent-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-that-agent"></a></h3>
<h3 class="heading settled" data-level="2.7" id="it-should-be-possible-for-an-agent-with-control-access-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-any-agent"><span class="secno">2.7. </span><span class="content">It should be possible for an agent with Control access to block/allow certain apps from accessing a specific resource as any agent</span><a class="self-link" href="#it-should-be-possible-for-an-agent-with-control-access-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-any-agent"></a></h3>
<div class="assertion no-marker">
<div class="marker">Use cases</div>
<li data-md>
<p><a href="#chat-with-doctor">§ 3.3 Chat with doctor</a></p>
<h3 class="heading settled" data-level="2.8" id="it-should-be-easy-to-allow-others-accessing-your-resources-to-use-apps-youre-okay-without-requiring-your-explicit-consent"><span class="secno">2.8. </span><span class="content">It should be easy to allow others accessing your resources to use apps you’re okay without requiring your explicit consent.</span><a class="self-link" href="#it-should-be-easy-to-allow-others-accessing-your-resources-to-use-apps-youre-okay-without-requiring-your-explicit-consent"></a></h3>
<h3 class="heading settled" data-level="2.9" id="access-to-specific-types-of-data-should-extend-to-new-resources-that-contain-that-data"><span class="secno">2.9. </span><span class="content">Access to specific types of data should extend to new resources that contain that data</span><a class="self-link" href="#access-to-specific-types-of-data-should-extend-to-new-resources-that-contain-that-data"></a></h3>
<h3 class="heading settled" data-level="2.10" id="access-to-specific-types-of-data-should-not-expose-other-data-that-was-not-requested"><span class="secno">2.10. </span><span class="content">Access to specific types of data should not expose other data that was not requested</span><a class="self-link" href="#access-to-specific-types-of-data-should-not-expose-other-data-that-was-not-requested"></a></h3>
<h3 class="heading settled" data-level="2.11" id="data-should-have-different-levels-of-requirements-for-users-conciousness-in-consent"><span class="secno">2.11. </span><span class="content">Data should have different levels of requirements for user’s conciousness in consent</span><a class="self-link" href="#data-should-have-different-levels-of-requirements-for-users-conciousness-in-consent"></a></h3>
<h3 class="heading settled" data-level="2.12" id="the-authorization-data-is-easily-cachable"><span class="secno">2.12. </span><span class="content">The authorization data is easily cachable</span><a class="self-link" href="#the-authorization-data-is-easily-cachable"></a></h3>
<h3 class="heading settled" data-level="2.13" id="information-about-clients-apps-to-which-users-have-granted-access-and-what-specific-access-they-have-delegated-should-not-be-made-available-to-resource-servers-that-do-not-enforce-relevant-access-restrictions-on-those-clients"><span class="secno">2.13. </span><span class="content">Information about Clients (apps) to which users have granted access and what specific access they have delegated should not be made available to Resource Servers that do not enforce relevant access restrictions on those Clients.</span><a class="self-link" href="#information-about-clients-apps-to-which-users-have-granted-access-and-what-specific-access-they-have-delegated-should-not-be-made-available-to-resource-servers-that-do-not-enforce-relevant-access-restrictions-on-those-clients"></a></h3>
<h2 class="heading settled" data-level="3" id="use-cases"><span class="secno">3. </span><span class="content">Use Cases</span><a class="self-link" href="#use-cases"></a></h2>
<p class="issue" id="issue-5636bec6"><a class="self-link" href="#issue-5636bec6"></a> Each use case needs an author who can provide further clarifications as needed.</p>
<h3 class="heading settled" data-level="3.1" id="simple-game"><span class="secno">3.1. </span><span class="content">Simple game</span><a class="self-link" href="#simple-game"></a></h3>
<li data-md>
<p>Alice uses https://simplegame.example to play a singleplayer game</p>
<li data-md>
<p>Simplegame only needs some file somewhere that it can write its own configuration to. It does not care where it is</p>
<li data-md>
<p>Simpleapp will also need to access this file again even if it’s being used on another machine</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-resource">§ 2.2 An app can request access to a specific resource</a></p>
<h3 class="heading settled" data-level="3.2" id="chat-with-friends"><span class="secno">3.2. </span><span class="content">Chat with friends</span><a class="self-link" href="#chat-with-friends"></a></h3>
<li data-md>
<p>Alice uses to chat with her friends</p>
<li data-md>
<p>OChat wants to gain access to all chat related data</p>
<li data-md>
<p>Wants access to chat related data that was created after it asked for permission to read them</p>
<li data-md>
<p>Wants to be alerted when new chat related data has been added to the Pod</p>
<li data-md>
<p>Wants to create chat related data</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod">§ 2.3 An app can request access to a specific type of data without knowing the structure of resources on a Pod</a></p>
<h3 class="heading settled" data-level="3.3" id="chat-with-doctor"><span class="secno">3.3. </span><span class="content">Chat with doctor</span><a class="self-link" href="#chat-with-doctor"></a></h3>
<li data-md>
<p>Alice uses https://doctorChat.example to chat with her doctor</p>
<li data-md>
<p>DoctorChat wants to create chat related data specifically about medical information</p>
<li data-md>
<p>DoctorChat wants to ensure Alice has given explicit consent to view the chats that it created before other apps can view this data</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#it-should-be-possible-for-an-agent-with-control-access-to-block-allow-certain-apps-from-accessing-a-specific-resource-as-any-agent">§ 2.7 It should be possible for an agent with Control access to block/allow certain apps from accessing a specific resource as any agent</a></p>
<h3 class="heading settled" data-level="3.4" id="discussion-boards"><span class="secno">3.4. </span><span class="content">Discussion boards</span><a class="self-link" href="#discussion-boards"></a></h3>
<li data-md>
<p>Alice uses iSay deployed on https://isay.alice.example/ to participate in discussion boards</p>
<li data-md>
<p>She wants to trust iSay to access any discussion boards, including</p>
<li data-md>
<p>Discussions on https://alice.example/</p>
<li data-md>
<p>Discussions on https://acme.example/</p>
<li data-md>
<p>Discussion on https://yoyodyne.example/</p>
<li data-md>
<p>She wants to receive push notifications on devices she uses when someone replies to discussion she participates in - iSay inculdes a remote client component which provides that feature.</p>
<li data-md>
<p>Alice, ACME and Yoyodyne want to allow each person with access to discussion boards on their resource servers to decide which applications they trust to participate in those discussions.</p>
<li data-md>
<p>Alice only wants to allow iSay to access discussions to avoid other apps (eg. games) she tries to have any way of posting spam messges in any of those discussions</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#the-system-is-not-abusable">§ 2.1 The system is not abusable</a></p>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod">§ 2.3 An app can request access to a specific type of data without knowing the structure of resources on a Pod</a></p>
<h3 class="heading settled" data-level="3.5" id="rdf-editor"><span class="secno">3.5. </span><span class="content">RDF editor</span><a class="self-link" href="#rdf-editor"></a></h3>
<li data-md>
<p>Alice uses to edit her raw RDF</p>
<li data-md>
<p>OEdit wants to be able to read and write to a file at a specific location</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-resource">§ 2.2 An app can request access to a specific resource</a></p>
<h3 class="heading settled" data-level="3.6" id="pod-administration"><span class="secno">3.6. </span><span class="content">Pod administration</span><a class="self-link" href="#pod-administration"></a></h3>
<li data-md>
<p>Alice uses https://admin.example to control her pod</p>
<li data-md>
<p>Admin wants to be able to read and write to all files on a user’s Pod</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-resource">§ 2.2 An app can request access to a specific resource</a></p>
<h3 class="heading settled" data-level="3.7" id="photos-viewer"><span class="secno">3.7. </span><span class="content">Photos viewer</span><a class="self-link" href="#photos-viewer"></a></h3>
<li data-md>
<p>Alice uses https://decentPhotos.example to view her photos and her friend Bob’s photos</p>
<li data-md>
<p>Decent photos wants to read to all photos on Alice’s Pod</p>
<li data-md>
<p>Wants to read all photos on Bob’s Pod that Alice has access to</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod">§ 2.3 An app can request access to a specific type of data without knowing the structure of resources on a Pod</a></p>
<h3 class="heading settled" data-level="3.8" id="photos-organizer"><span class="secno">3.8. </span><span class="content">Photos organizer</span><a class="self-link" href="#photos-organizer"></a></h3>
<li data-md>
<p>Alice uses https://photoOrganizer.example to organize the photos on her Pod</p>
<li data-md>
<p>PhotoOrganizer wants to read and write only photos</p>
<li data-md>
<p>Wants to understand the folder structure of the Pod</p>
<li data-md>
<p>Wants to modify the folder structure of the Pod</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod">§ 2.3 An app can request access to a specific type of data without knowing the structure of resources on a Pod</a></p>
<h3 class="heading settled" data-level="3.9" id="photos-processing"><span class="secno">3.9. </span><span class="content">Photos processing</span><a class="self-link" href="#photos-processing"></a></h3>
<li data-md>
<p>Alice uses FaceDetectionCronJob to crawl over her photos and Bob’s photos at night and produce facial recognition data</p>
<li data-md>
<p>FaceDetectionCronJob is not an application and will need access to photos even when Alice is not actively using it</p>
<li data-md>
<p>Wants to have read access to Alice’s photos</p>
<li data-md>
<p>Wants to know where it should put its facial detection data</p>
<li data-md>
<p>Wants to have read access to Bob’s photos that Alice has access to</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#an-app-can-request-access-to-a-specific-type-of-data-without-knowing-the-structure-of-resources-on-a-pod">§ 2.3 An app can request access to a specific type of data without knowing the structure of resources on a Pod</a></p>
<li data-md>
<p><a href="#apps-can-request-the-ability-to-write-a-specific-type-of-data-and-will-be-told-where-it-should-write-it">§ 2.5 Apps can request the ability to write a specific type of data and will be told where it should write it</a></p>
<h3 class="heading settled" data-level="3.10" id="evil-fitness-tracker"><span class="secno">3.10. </span><span class="content">Evil fitness tracker</span><a class="self-link" href="#evil-fitness-tracker"></a></h3>
<li data-md>
<p>Alice accidentally uses https://evilfitbit.example to track her fitness data</p>
<li data-md>
<p>Evilfitbit will try to do everything to get Alice’s financial data while pretending to just track her fitness data (This should not be allowed)</p>
<div class="assertion no-marker">
<div class="marker">Requirements</div>
<li data-md>
<p><a href="#the-system-is-not-abusable">§ 2.1 The system is not abusable</a></p>
<h3 class="heading settled" data-level="3.11" id="finances-tracker"><span class="secno">3.11. </span><span class="content">Finances tracker</span><a class="self-link" href="#finances-tracker"></a></h3>
<li data-md>
<p>Alice uses https://financeTracker.example to view her current finances</p>
<li data-md>
<p>financeTracker wants to be able to read Alice’s Financial data</p>
<li data-md>
<p>financeTracker wants to be able to keep a backup of Alice’s data</p>
<li data-md>
<p>Alice wants to ensure that financeTracker isn’t legally allowed to save the data it receives</p>
<h3 class="heading settled" data-level="3.12" id="restaurants-tracker"><span class="secno">3.12. </span><span class="content">Restaurants tracker</span><a class="self-link" href="#restaurants-tracker"></a></h3>
<li data-md>
<p>Alice uses https://favoriteRestaurants.example to track the restaurants she likes</p>
<li data-md>
<p>Favorite Restaurants wants to read and write data about restaurants and to get the Alice’s location</p>
<li data-md>
<p>Alice only wants to allow Favorite Restaurants to read and write restaurant data but not to get her location</p>
<h3 class="heading settled" data-level="3.13" id="blogs"><span class="secno">3.13. </span><span class="content">Blogs</span><a class="self-link" href="#blogs"></a></h3>
<li data-md>
<p>Alice uses https://blogs.example to read and write blogs</p>
<li data-md>
<p>Blogs wants to be able to read public blog information and to write blog data to Alice’s Pod</p>
<li data-md>
<p>Blogs wants to read data about Alice’s interests</p>
<li data-md>
<p>Alice does not want Blogs to get data about her interests</p>
<li data-md>
<p>Blogs continually asks Alice to grant it access to her interests and Alice is annoyed with the incessant asking</p>
<li data-md>
<p>Alice uses, is developing, or is testing an app deployed to http://localhost:8080</p>
<li data-md>
<p>Note that Alice’s Identity Provider can’t reach Alice’s `localhost:8080`</p>
<li data-md>
<p>Note that Alice’s Pod can’t reach Alice’s `localhost:8080`</p>
<li data-md>
<p>Alice uses an app deployed behind a NAT or firewall (while her browser is also behind the same NAT or firewall) that accesses resources outside the NAT or firewall; for example, Alice uses to edit code stored in Customer Bob’s Pod</p>
<li data-md>
<p>*CoolCode* is deployed behind Enterprise.Example’s company firewall and is not dereferenceable from the outside, for example because</p>
<li data-md>
<p>*CoolCode* is proprietary to Enterprise.Example; or</p>
<li data-md>
<p>*CoolCode* is a commercial product that is deployed on-premises at Enterprise.Example’s datacenter</p>
<li data-md>
<p>Note that Alice’s Identity Provider can’t reach</p>
<li data-md>
<p>Note that Customer Bob’s Pod can’t reach</p>
<h3 class="heading settled" data-level="3.14" id="custom-tls-ca"><span class="secno">3.14. </span><span class="content">Custom TLS CA</span><a class="self-link" href="#custom-tls-ca"></a></h3>
<li data-md>
<p>Alice uses https://photoOrganizer.example to organize photos on her company’s private storage server https://storage.private.enterprise.example</p>
<li data-md>
<p>`storage.private.enterprise.example`'s TLS certificate is signed by Enterprise.Example’s private Certificate Authority</p>
<li data-md>
<p>Alice’s web browser is configured to trust Enterprise.Example’s private Certificate Authority</p>
<li data-md>
<p>`storage.private.enterprise.example` is reachable from the public Internet, so Alice’s Identity Provider and *photoOrganizer* could reach it; however, neither is configured to trust Enterprise.Example’s private Certificate Authority</p>
<div data-fill-with="conformance">
<h2 class="no-ref no-num heading settled" id="conformance"><span class="content"> Conformance</span><a class="self-link" href="#conformance"></a></h2>
<p> Conformance requirements are expressed with a combination of descriptive assertions and RFC 2119 terminology.
in the normative parts of this document
are to be interpreted as described in RFC 2119.
However, for readability,
these words do not appear in all uppercase letters in this specification. </p>
<p> All of the text of this specification is normative
except sections explicitly marked as non-normative, examples, and notes. <a data-link-type="biblio" href="#biblio-rfc2119">[RFC2119]</a> </p>
<p> Examples in this specification are introduced with the words “for example”
or are set apart from the normative text with <code>class="example"</code>, like this: </p>
<div class="example" id="example-example"><a class="self-link" href="#example-example"></a> This is an example of an informative example. </div>
<p> Informative notes begin with the word “Note”
and are set apart from the normative text with <code>class="note"</code>, like this: </p>
<p class="note" role="note"> Note, this is an informative note. </p>
<h2 class="no-num no-ref heading settled" id="references"><span class="content">References</span><a class="self-link" href="#references"></a></h2>
<h3 class="no-num no-ref heading settled" id="normative"><span class="content">Normative References</span><a class="self-link" href="#normative"></a></h3>
<dt id="biblio-rfc2119">[RFC2119]
<dd>S. Bradner. <a href="">Key words for use in RFCs to Indicate Requirement Levels</a>. March 1997. Best Current Practice. URL: <a href=""></a>
<h2 class="no-num no-ref heading settled" id="issues-index"><span class="content">Issues Index</span><a class="self-link" href="#issues-index"></a></h2>
<div style="counter-reset:issue">
<div class="issue"> Needs explaination how proposals should clearly reference requirements which they satisfy. As well as requirements they do not satisfy due to some limitations.<a href="#issue-c29b11aa"> ↵ </a></div>
<div class="issue"> Each use case needs an author who can provide further clarifications as needed.<a href="#issue-5636bec6"> ↵ </a></div>
