Aaron Parecki

@aaronpk.com

#OAuth #IndieWeb

TIL about UIScreenshotService which enables iOS apps to provide a high res PDF screenshot of the app content when the user uses the system screenshot action! Chrome uses this to give a full export of the page!

I'm impressed, Cathay Pacific transferred my vegetarian meal request to the new flight they moved me to after the incoming flight was late and missed the connection. Normally airlines say oh well you didn't reserve the meal 72 hours before the flight.

I'm setting up a temporary laptop for my next trip and it's shocking how much faster the cross-device passkey flow is compared to looking up and hand typing my long 1Password passwords

"I'll just check my critical thinking and nuke it in the microwave" has to be my favorite quote from this Business Insider video on Trader Joe's white-labeled food

Me looking at my todo list on a Sunday night after having done at least a couple things today, yet somehow it looks more like a list of what I did *not* do today.

oh no, due to a series of misclicks, I just accidentally archived the most recent 100 emails in my inbox. if nothing else, reviewing my "all mail" folder is doing a good job of making me question how important emails in my inbox actually are.

The new MCP spec just dropped! 🎉 There's too many new things to get into everything, but there are two big changes I am most excited about 👀 📝 Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control

The IETF OAuth Working Group has adopted the Client ID Metadata Document specification! > This specification defines a mechanism through which an OAuth client can identify itself to authorization servers, without prior dynamic client registration or other existing registration.

The IETF OAuth Working Group has adopted the Identity Assertion Authorization Grant specification! datatracker.ietf.org/doc/draft-ie... This is the basis of Cross App Access (XAA), providing IT admins better visibility and control by configuring the app-to-app connections in their enterprise IdP.

Identity Assertion Authorization Grant

This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through a common enterprise identity provider us...

datatracker.ietf.org

Well that's the last time I take my ID out of my wallet to go through airport security. I made the mistake of putting it into my pocket instead of back in my wallet and it seems to have fallen out somewhere between PDX and SFO 🫠

I just got FreePBX up and running and connected to a WiFi phone and my doorbell and video intercom system! I have two way calling between every device, I can even connect analog phones!

Bild

The latest version of the MCP spec is now officially 2025-06-18! Congrats to everyone in the MCP community involved in making this happen! Key updates to the authorization section 👇

I've got 22 hours in Hong Kong on a layover and I'm staying overnight in a hotel near the old Kowloon Walled City. Any tips for what I should do on this very short trip?

The building that collapsed from the earthquake was right next to the train station we got off at when we arrived in Bangkok last weekend. We took the train from Chiang Mai to Chatuchak 😮

Chase sends 8-digit 2fa SMS codes, which seems excessive compared to the 6 that most other places use, but even weirder is that the first digit of them has always been the same, effectively making it a 7 digit code. Anyone know what's up with that?

At long last, the OAuth working group has finished the Best Current Practice for OAuth 2.0 Security and it was just published as RFC9700! This has been a long time in the works, and I'm very thankful to everyone who has helped out with it over the years! www.rfc-editor.org/rfc/rfc9700....

RFC 9700: Best Current Practice for OAuth 2.0 Security

This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experience...

rfc-editor.org

Every now and then I remember how in 2014 I mined $20 worth of dogecoin, then said this is stupid and exchanged it for 0.05 bitcoin sent to a brainwallet. I can't remember the seed phrase, so it's just stuck in the blockchain, and is now worth $5000

I am still getting monthly emails saying I have a $0 balance from the tenant portal of the apartment we moved out of 18 months ago. Today I logged in to see if I can delete my account, but instead I see new maintenance requests from the last few months 😮