No Description
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

xep-0276.xml 13KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249
  1. <?xml version='1.0' encoding='UTF-8'?>
  2. <!DOCTYPE xep SYSTEM 'xep.dtd' [
  3. <!ENTITY % ents SYSTEM 'xep.ent'>
  4. %ents;
  5. ]>
  6. <?xml-stylesheet type='text/xsl' href='xep.xsl'?>
  7. <xep>
  8. <header>
  9. <title>Presence Decloaking</title>
  10. <abstract>This specification defines an XMPP protocol extension that enables a user to send directed presence with a request for the target to also share presence information for the duration of a communications session.</abstract>
  11. &LEGALNOTICE;
  12. <number>0276</number>
  13. <status>Deferred</status>
  14. <type>Standards Track</type>
  15. <sig>None</sig>
  16. <approver>Council</approver>
  17. <dependencies/>
  18. <supersedes/>
  19. <supersededby/>
  20. <shortname>NOT YET ASSIGNED</shortname>
  21. <author>
  22. <firstname>Simon</firstname>
  23. <surname>McVittie</surname>
  24. <email>simon.mcvittie@collabora.co.uk</email>
  25. <jid>simon.mcvittie@collabora.co.uk</jid>
  26. </author>
  27. &stpeter;
  28. &robmcqueen;
  29. <revision>
  30. <version>0.3</version>
  31. <date>2012-07-13</date>
  32. <initials>psa</initials>
  33. <remark><p>Tweaked the security considerations.</p></remark>
  34. </revision>
  35. <revision>
  36. <version>0.2</version>
  37. <date>2012-07-11</date>
  38. <initials>psa</initials>
  39. <remark><p>Back by popular demand; also changed namespace to decloak (again).</p></remark>
  40. </revision>
  41. <revision>
  42. <version>0.1</version>
  43. <date>2010-01-26</date>
  44. <initials>psa</initials>
  45. <remark><p>Initial published version as accepted for publication by the XMPP Council; more fully described the reasons for using directed presence instead of presence subscriptions; changed requested namespace from decloak to temppres.</p></remark>
  46. </revision>
  47. <revision>
  48. <version>0.0.2</version>
  49. <date>2010-01-17</date>
  50. <initials>psa</initials>
  51. <remark><p>Rewrote the introduction, clarified the security considerations, requested issuance of an appropriate URN from the XMPP Registrar.</p></remark>
  52. </revision>
  53. <revision>
  54. <version>0.0.1</version>
  55. <date>2010-01-05</date>
  56. <initials>smcv/psa/rm</initials>
  57. <remark><p>First draft.</p></remark>
  58. </revision>
  59. </header>
  60. <section1 topic='Introduction' anchor='intro'>
  61. <p>Various XMPP extensions, such as &xep0166;, require additional support from clients, advertised in presence via &xep0115;, or require that IQ stanzas are sent to a particular resource. For instance, Jingle calls can be made only by sending an IQ to a particular resource. However, two parties who wish to communicate do not always share presence information through subscriptions and therefore cannot use entity capabilities to determine the proper full JID for communication. Indeed, one of the parties might not even use XMPP: e.g., a remote user on the other side of a gateway to a network based on the Session Initiation Protocol (SIP; &rfc3261;) or to the Public Switched Telephone Network (PSTN). It would be helpful if a user could make a call through such a gateway by typing the SIP URI or telephone number of an arbitrary contact, without first exchanging presence.</p>
  62. <p>&rfc6121; already defines a way to send directed presence to another entity. This document supplements RFC 6121 by defining an XML protocol extension enabling two parties to explicitly share presence with each other on a temporary basis through an "intentional presence leak"; we call this "decloaking".</p>
  63. <p>Note: This protocol has already been implemented using an XML namespace of "http://telepathy.freedesktop.org/xmpp/protocol/decloak" but the &REGISTRAR; was requested to issue the XMPP URN "urn:xmpp:decloak:0" upon publication of this proposal in the &xep0001; series.</p>
  64. </section1>
  65. <section1 topic='Requirements' anchor='reqs'>
  66. <p>An entity should be able to attempt to initiate a communication session that requires IQs and/or capability negotiation (Jingle, a file transfer, end-to-end encryption, or other similar communication modes) with an arbitrary entity.</p>
  67. <p>If the receiving entity agrees to divulge their presence in this way, minimal presence (with no 'type' attribute, &SHOW; element, avatar hash, etc.) and capabilities should be communicated to the initiating entity, so that the initiating entity can continue to initiate the communication session.</p>
  68. </section1>
  69. <section1 topic='Approach' anchor='approach'>
  70. <p>The approach taken here is that the user who wishes to initiate presence sharing for the length of a communications session sends directed presence (including entity capabilities) to the bare JID &LOCALBARE; of the initiator's intended communication partner, including a special XMPP extension &lt;decloak xmlns='urn:xmpp:decloak:0'/&gt;. Upon receipt of this directed presence stanza, if configured to do so the recipient's sends directed presence (including entity capabilities) to the initiator's full JID &LOCALFULL;. Once the parties complete their communications session, they can terminate presence sharing by sending directed &lt;presence type='unavailable'/&gt; to each other; alternatively, at any time they could "upgrade" their session-based presence sharing to a full XMPP presence subscription as described in &xmppim;.</p>
  71. <p>Although the &lt;decloak/&gt; element could be sent in presence stanzas of type "subscribe" instead of in directed presence notifications, that behavior is discouraged because the "fall-through" case for subscription requests is a long-lived subscription, not temporary sharing of presence information for the life of a communication session.</p>
  72. </section1>
  73. <section1 topic='Scenario' anchor='scenario'>
  74. <p>Suppose that Juliet wishes to make a media call to Tybalt, but the two parties do not share presence information in accordance with the core definition of XMPP. Suppose also that Juliet and Tybalt have the following presence, although neither can initially see the other's presence:</p>
  75. <example caption="Initial state">
  76. <![CDATA[
  77. <presence from='juliet@shakespeare.lit/balcony'>
  78. <show>dnd</show>
  79. <status>on the phone</status>
  80. <c ver='juliet-caps-hash' .../>
  81. </presence>
  82. <presence from='tybalt@shakespeare.lit/library'>
  83. <show>dnd</show>
  84. <status>researching</status>
  85. <c ver='tybalt-caps-hash' .../>
  86. </presence>
  87. <presence from='tybalt@shakespeare.lit/garden'>
  88. <show>xa</show>
  89. <status>gone to the library</status>
  90. <c ver='tybalt-caps-hash' .../>
  91. </presence>
  92. ]]></example>
  93. <p>Juliet requests that Tybalt divulge his availability and capabilities, by sending directed presence to his bare JID &lt;tybalt@shakespeare.lit&gt;, where the presence stanza contains a &lt;decloak/&gt; element.</p>
  94. <example caption="Requesting that a peer share session presence"><![CDATA[
  95. <presence from='juliet@shakespeare.lit/balcony'
  96. to='tybalt@shakespeare.lit'>
  97. <c ver='juliet-caps-hash' .../>
  98. <decloak xmlns='urn:xmpp:decloak:0' reason='media'/>
  99. </presence>
  100. ]]></example>
  101. <p>Tybalt MAY in response send session presence from one or more resources, by sending directed presence from those resource(s) to Juliet's bare JID.</p>
  102. <example caption="Sharing presence in response to a request">
  103. <![CDATA[
  104. <presence from='tybalt@shakespeare.lit/library'
  105. to='juliet@shakespeare.lit'>
  106. <c ver='tybalt-caps-hash' .../>
  107. </presence>
  108. <presence from='tybalt@shakespeare.lit/garden'
  109. to='juliet@shakespeare.lit'>
  110. <c ver='tybalt-caps-hash' .../>
  111. </presence>
  112. ]]></example>
  113. <p>Once Juliet has received the session presence from Tybalt, if necessary she can perform service discovery to find out the meaning of the entity capabilities hashes (if unknown), then proceed to make a Jingle call, initiate a file transfer, or complete some other use case.</p>
  114. <p>Naturally, it's also possible that Tybalt's client will ignore the request (in particular, this will happen for any resource that does not implement this specification). However, in this case the parties are no worse off than they were before Juliet requested decloaking.</p>
  115. </section1>
  116. <section1 topic='Sharing Presence with a Gateway' anchor='gateway'>
  117. <p>Let us now suppose that Juliet wishes to make a media call to Romeo, who does not use XMPP but who has a SIP URI of sip:romeo@shakespeare.lit, which can be called via an XMPP-to-SIP gateway.</p>
  118. <p>Juliet requests that the SIP contact representing Romeo on the gateway shall divulge its availability and capabilities, by sending directed presence to its bare JID at the gateway containing a &lt;decloak/&gt; element.</p>
  119. <example caption="Requesting that a gateway contact shall share session presence">
  120. <![CDATA[
  121. <presence from='juliet@shakespeare.lit/balcony'
  122. to='romeo%shakespeare.lit@sip.shakespeare.lit'>
  123. <c ver='juliet-caps-hash' .../>
  124. <decloak xmlns='urn:xmpp:decloak:0' reason='media'/>
  125. </presence>
  126. ]]></example>
  127. <p>In response, the SIP gateway automatically shares session presence on behalf of that JID, in order to tell Juliet what the gateway's capabilities are.</p>
  128. <example caption="Sharing presence in response to a request">
  129. <![CDATA[
  130. <presence from='romeo%shakespeare.lit@sip.shakespeare.lit'
  131. to='juliet@shakespeare.lit'>
  132. <c ver='gateway-caps-hash' .../>
  133. </presence>
  134. ]]></example>
  135. <p>As above, Juliet can now complete service discovery and any protocol-specific use cases.</p>
  136. </section1>
  137. <section1 topic='The reason Attibute' anchor='reason'>
  138. <p>To signal the type of communication that is desired, the entity that first shares session presence MAY include a 'reason' attribute on the &lt;decloak/&gt; element. The following values for the 'reason' attribute are defined:</p>
  139. <dl>
  140. <di>
  141. <dt>media</dt>
  142. <dd>Presence is requested for a voice and/or video call, e.g. via &xep0167;.</dd>
  143. </di>
  144. <di>
  145. <dt>text</dt>
  146. <dd>Presence is requested for a textual conversation using an extension that requires capabilities to be disclosed, such as &xep0071;, &xep0085;, &xep0301;, or end-to-end encryption.</dd>
  147. </di>
  148. <di>
  149. <dt>file</dt>
  150. <dd>Presence is requested for one or more file transfers, e.g. via &xep0234; or &xep0095;.</dd>
  151. </di>
  152. </dl>
  153. <p>Inclusion of the 'reason' attribute can be interpreted by the receiving client as a signal that communication is about to start; for instance, a call accept/reject dialog could double as a UI for accepting or rejecting a session presence request.</p>
  154. </section1>
  155. <section1 topic='Business Rules' anchor='bizrules'>
  156. <p>To limit the extent of the presence leak, the receiving entity SHOULD send only bare presence without the XMPP &PRIORITY;, &SHOW;, or &STATUS; element. Unfortunately, this has two implications:</p>
  157. <ol>
  158. <li><p>The initiating entity cannot know which of the receiving entity's resources is more likely to engage in communication. This might imply that the initiating entity will need to send a session initiation request or other communication to more than one of the receiving entity's resources (and then retract the session initiation requests that are not answered by the receiving entity). Solutions to that problem are out of scope for this specification.</p></li>
  159. <li><p>Establishment of a session might be delayed (e.g., because in Jingle it is desirable to start negotiating candidates as soon as possible but a user interface that prompts the receiving entity to explicitly approve of divulging presence will tend to a delay in call setup). As a result, it may be advantageous to have a way to configure unconditional sharing of session presence in certain deployments, at least within the same trust domain.</p></li>
  160. </ol>
  161. </section1>
  162. <section1 topic='Security Considerations' anchor='security'>
  163. <p>Because decloaking is a presence leak (albeit intentional), an XMPP client that implements the receiving side of this specification MUST disable sharing of session presence by default and MUST enable the feature only as a result of explicit user confirmation. Such confirmation can be provided per request, at the first request per requestor, by setting some "always decloak" configuration option (e.g., globally or per domain), or through some other suitable means as long as decloaking does not occur by default. (Gateways and other non-user entities MAY divulge their own presence and capabilities unconditionally, if that is appropriate for the service policy at the gateway.)</p>
  164. </section1>
  165. <section1 topic='IANA Considerations' anchor='iana'>
  166. <p>This document requires no interaction with &IANA;.</p>
  167. </section1>
  168. <section1 topic='XMPP Registrar Considerations' anchor='registrar'>
  169. <p>The XMPP Registrar is requested to issue an initial namespace of "urn:xmpp:decloak:0".</p>
  170. </section1>
  171. <section1 topic='XML Schema' anchor='schema'>
  172. <code><![CDATA[
  173. <xs:schema
  174. xmlns:xs='http://www.w3.org/2001/XMLSchema'
  175. targetNamespace='urn:xmpp:decloak:0'
  176. xmlns='urn:xmpp:decloak:0'
  177. elementFormDefault='qualified'>
  178. <xs:element name='decloak'>
  179. <xs:complexType>
  180. <xs:simpleContent>
  181. <xs:extension base='empty'>
  182. <xs:attribute name='reason' use='optional' type='xs:string'/>
  183. </xs:extension>
  184. </xs:simpleContent>
  185. </xs:complexType>
  186. </xs:element>
  187. <xs:simpleType name='empty'>
  188. <xs:restriction base='xs:string'>
  189. <xs:enumeration value=''/>
  190. </xs:restriction>
  191. </xs:simpleType>
  192. </xs:schema>
  193. ]]></code>
  194. </section1>
  195. <section1 topic='Acknowledgements' anchor='ack'>
  196. <p>The need for this protocol extension, and a rough proposal for solving the problem, were originally determined at XMPP Summit 5 in the summer of 2007. Thanks to Diana Cionoiu, Justin Karneges, and Justin Uberti for their input to those discussions. Thanks also to Kurt Zeilenga for his feedback on the resulting specification.</p>
  197. </section1>
  198. </xep>