Mounting Web Distributed Authoring and Versioning (WebDAV) Servers

Similar documents
Network Working Group Internet-Draft October 27, 2007 Intended status: Experimental Expires: April 29, 2008

Network Working Group. Category: Informational January 2006

vcard Extensions for Instant Messaging (IM)

Category: Standards Track May Transport Layer Security Protocol Compression Methods

Network Working Group. OSAF February Quota and Size Properties for Distributed Authoring and Versioning (DAV) Collections

Category: Standards Track September MIB Textual Conventions for Uniform Resource Identifiers (URIs)

Category: Standards Track October 2006

Network Working Group. Category: Standards Track August Dynamic Host Configuration Protocol for IPv6 (DHCPv6) Relay Agent Remote-ID Option

Network Working Group Internet-Draft August 2005 Expires: February 2, Atom Link No Follow draft-snell-atompub-feed-nofollow-00.

Network Working Group. Category: Standards Track DENIC eg January 2005

Category: Standards Track June Requesting Attributes by Object Class in the Lightweight Directory Access Protocol (LDAP) Status of This Memo

Request for Comments: 4329 April 2006 Category: Informational

Network Working Group Request for Comments: 4913 Category: Experimental July 2007

Request for Comments: 4633 Category: Experimental August 2006

Internet Engineering Task Force (IETF) Category: Standards Track ISSN: July 2012

Jabber, Inc. August 20, 2004

Request for Comments: 4680 Updates: 4346 September 2006 Category: Standards Track

Category: Standards Track October 2006

Network Working Group Request for Comments: 4424 February 2006 Updates: 4348 Category: Standards Track

Category: Standards Track June 2006

Network Working Group Internet-Draft August 2005 Expires: February 2, Atom Link No Follow draft-snell-atompub-feed-nofollow-03.

Network Working Group. Intended status: Standards Track Columbia U. Expires: March 5, 2009 September 1, 2008

Request for Comments: 5179 Category: Standards Track May 2008

Intended status: Informational. B. Wyman October 2, 2007

Network Working Group Internet-Draft January 25, 2006 Expires: July 29, Feed Rank draft-snell-atompub-feed-index-05.txt. Status of this Memo

Network Working Group Request for Comments: 3937 Category: Informational October 2004

Network Working Group. Category: Standards Track June Dynamic Host Configuration Protocol for IPv6 (DHCPv6) Relay Agent Subscriber-ID Option

Network Working Group Request for Comments: 4573 Category: Standard Track July MIME Type Registration for RTP Payload Format for H.

Category: Standards Track December 2007

Network Working Group Request for Comments: 2318 Category: Informational W3C March 1998

Request for Comments: 3934 Updates: 2418 October 2004 BCP: 94 Category: Best Current Practice

Request for Comments: 4393 Category: Standards Track March MIME Type Registrations for 3GPP2 Multimedia Files

Request for Comments: 5397 Category: Standards Track December 2008

WebDAV Current Principal Extension

Internet Engineering Task Force (IETF) February The application/tei+xml Media Type. Abstract

Expires: October 9, 2005 April 7, 2005

Request for Comments: 3861 Category: Standards Track August 2004

Network Working Group. February 2005

Request for Comments: May 2007

Request for Comments: K. Norrman Ericsson June 2006

Category: Standards Track October Vendor-Identifying Vendor Options for Dynamic Host Configuration Protocol version 4 (DHCPv4)

Category: Standards Track Cisco H. Tschofenig Nokia Siemens Networks August 2008

Intended status: Standards Track August 15, 2008 Expires: February 16, 2009

Network Working Group Request for Comments: 4869 Category: Informational May Suite B Cryptographic Suites for IPsec. Status of This Memo

Network Working Group. Category: Standards Track July 2007

Request for Comments: 5079 Category: Standards Track December Rejecting Anonymous Requests in the Session Initiation Protocol (SIP)

Network Working Group Request for Comments: 4143 Category: Standards Track Brandenburg November 2005

Expires in six months 24 October 2004 Obsoletes: RFC , , 3377, 3771

September The Internet Assigned Number Authority (IANA) tel Uniform Resource Identifier (URI) Parameter Registry. Status of This Memo

Obsoletes: 2070, 1980, 1942, 1867, 1866 Category: Informational June 2000

Request for Comments: 3968 Updates: 3427 December 2004 BCP: 98 Category: Best Current Practice

Network Working Group. Category: Standards Track June 2005

Network Working Group Request for Comments: August Address-Prefix-Based Outbound Route Filter for BGP-4

Network Working Group Request for Comments: 5235 January 2008 Obsoletes: 3685 Category: Standards Track

Isode Limited March 2008

Request for Comments: 5010 Category: Standards Track Cisco Systems, Inc. September 2007

Category: Standards Track Cisco Systems, Inc January The Secure Shell (SSH) Session Channel Break Extension

Network Working Group. Cisco Systems June 2007

Request for Comments: 3932 October 2004 BCP: 92 Updates: 3710, 2026 Category: Best Current Practice

Network Working Group. N. Williams Sun Microsystems June 2006

Internet Engineering Task Force (IETF) Request for Comments: 5987 Category: Standards Track August 2010 ISSN:

Network Working Group. Category: Informational April A Uniform Resource Name (URN) Namespace for the Open Geospatial Consortium (OGC)

Category: Standards Track July The Post Office Protocol (POP3) Simple Authentication and Security Layer (SASL) Authentication Mechanism

Network Working Group. Category: Informational October 2005

Request for Comments: 4509 Category: Standards Track May Use of SHA-256 in DNSSEC Delegation Signer (DS) Resource Records (RRs)

Category: Standards Track Cisco Systems, Inc. March 2005

Network Working Group Request for Comments: Cisco Systems, Inc. December 2005

Request for Comments: 4255 Category: Standards Track SPARTA January Using DNS to Securely Publish Secure Shell (SSH) Key Fingerprints

Category: Informational September 2004

Category: Standards Track March Extensible Provisioning Protocol (EPP) Transport Over TCP

Request for Comments: Category: Standards Track January 2008

C. Martin ipath Services February A Policy Control Mechanism in IS-IS Using Administrative Tags

Network Working Group. Category: Standards Track Juniper Networks August 2008

Network Working Group Request for Comments: 4603 Category: Informational Cisco Systems July Additional Values for the NAS-Port-Type Attribute

Category: Informational October Common Format and MIME Type for Comma-Separated Values (CSV) Files

HIIT L. Eggert Nokia April Host Identity Protocol (HIP) Registration Extension

Request for Comments: 3764 Category: Standards Track April enumservice registration for Session Initiation Protocol (SIP) Addresses-of-Record

Network Working Group Request for Comments: 4432 March 2006 Category: Standards Track

Request for Comments: 4759 Category: Standards Track Neustar Inc. L. Conroy Roke Manor Research November 2006

Request for Comments: 4315 December 2005 Obsoletes: 2359 Category: Standards Track. Internet Message Access Protocol (IMAP) - UIDPLUS extension

Updates: 2409 May 2005 Category: Standards Track. Algorithms for Internet Key Exchange version 1 (IKEv1)

Internet Engineering Task Force (IETF) Request for Comments: 7237 Category: Informational June 2014 ISSN:

Network Working Group. Updates: 3463, 4468, 4954 June 2008 Category: Best Current Practice. A Registry for SMTP Enhanced Mail System Status Codes

Network Working Group. Obsoletes: 2717, Category: Best Current Practice Adobe Systems February 2006

Network Working Group. Category: Informational May OSPF Database Exchange Summary List Optimization

Request for Comments: 4571 Category: Standards Track July 2006

October Network News Transfer Protocol (NNTP) Extension for Streaming Feeds

Request for Comments: 4481 Columbia U. Category: Standards Track July 2006

Network Working Group Request for Comments: February 2006

Request for Comments: 4715 Category: Informational NTT November 2006

Request for Comments: 4142 Category: Standards Track Nine by Nine November 2005

Category: Experimental June 2006

Request for Comments: 5208 Category: Informational May 2008

Network Working Group. J. Lee Samsung Electronics T. Iwata Nagoya University August 2006

Network Working Group. Category: Standards Track Samsung S. Kumar Tech Mahindra Ltd S. Madanapalli Samsung May 2008

Network Working Group. Category: Informational SPARTA, Inc. S. Crocker Shinkuro Inc. S. Krishnaswamy SPARTA, Inc. August 2007

Internet Engineering Task Force (IETF) Request for Comments: 6266 Updates: 2616 June 2011 Category: Standards Track ISSN:

Category: Experimental April BinaryTime: An Alternate Format for Representing Date and Time in ASN.1

Network Working Group Request for Comments: 4147 Category: Informational August Proposed Changes to the Format of the IANA IPv6 Registry

Request for Comments: 5115 Category: Standards Track UCL January Telephony Routing over IP (TRIP) Attribute for Resource Priority

Transcription:

Network Working Group J. Reschke Request for Comments: 4709 greenbytes Category: Informational October 2006 Mounting Web Distributed Authoring and Versioning (WebDAV) Servers Status of this Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Copyright Notice Copyright The Internet Society (2006). All Rights Reserved. Abstract In current Web browsers, there is no uniform way to specify that a user clicking on a link will be presented with an editable view of a Web Distinguished Authoring and Versioning (WebDAV) server. For example, it is frequently desirable to be able to click on a link and have this link open a window that can handle drag-anddrop interaction with the resources of a WebDAV server. This document specifies a mechanism and a document format that enables WebDAV servers to send "mounting" information to a WebDAV client. The mechanism is designed to work on any platform and with any combination of browser and WebDAV client, relying solely on the well-understood dispatch of documents through their MIME type.

Table of Contents 1 Introduction...3 2 Terminology...4 3 Format...5 3.1 dm:mount... 5 3.2 dm:url... 5 3.3 dm:open...5 3.4 dm:username... 5 4 Example...6 5 Internationalization Considerations... 7 6 IANA Considerations... 8 6.1 MIME Type Registration... 8 7 Security Considerations... 10 8 Acknowledgements...11 9 References... 12 9.1 Normative References... 12 9.2 Informative References...12 A Alternative Approaches...13 A.1...Through HTML/CSS Extensions... 13 A.2...Through Custom URI Schemes...13 B Implementations... 14 B.1 Example Implementation for Webfolder Client...14 B.2 Xythos... 16 Index...17 Author's Address... 18 Intellectual Property and Copyright Statements... 18 Reschke Informational [Page 2]

1. Introduction By definition, a Web Distributed Authoring and Versioning (WebDAV) server ([RFC2518]) is an HTTP server as well ([RFC2616]). Most WebDAV servers can be (at least partly) operated from an HTML-based user interface in a web browser. However, it is frequently desirable to be able to switch from an HTML-based view to a presentation provided by a native WebDAV client, directly supporting the authoring features defined in WebDAV and related specifications. This document specifies a platform-neutral mechanism based on the dispatch of documents through their MIME type. For completeness, Appendix A lists other approaches that have been implemented in existing clients. For example, many educational institutions use WebDAV servers as a mechanism for sharing documents among students. Each student owns a separate collection structure on a WebDAV server, often called his/her "locker". Ideally, when users click on a link in an HTML page provided by the university (perhaps by their university Web portal), an editable view of their locker will appear. Reschke Informational [Page 3]

2. Terminology The terminology used here follows that in the WebDAV Distributed Authoring Protocol specification [RFC2518]. The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119]. This document uses XML DTD fragments ([XML]) as a purely notational convention. In particular: Element names use the namespace "http://purl.org/net/webdav/mount". When an XML element type in this namespace is referenced in this document outside of the context of an XML fragment, the string "dm:" will be prefixed to the element name. Element ordering is irrelevant. Extension elements/attributes (elements/attributes not already defined as valid child elements) may be added anywhere, except when explicitly stated otherwise. Reschke Informational [Page 4]

3. Format A WebDAV mount request is encoded in a specific XML format ([XML]) with a well-defined MIME type (see Section 6.1). The MIME type allows user agents to dispatch the content to a handler specific to the system's WebDAV client. The elements defined below use the namespace "http://purl.org/net/webdav/mount". <!ELEMENT mount (url, open?, username?) > <!ELEMENT url (#PCDATA) > <!-- PCDATA value: scheme ":" hier-part, as defined in Section 3 of [RFC3986] --> <!ELEMENT open (#PCDATA) > <!-- PCDATA value: path, as defined in Section 3 of [RFC3986] --> <!ELEMENT username (#PCDATA) > 3.1. dm:mount The <dm:mount> element acts as a container for all the remaining elements defined by this protocol. 3.2. dm:url The mandatory <dm:url> element provides the HTTP URL of the WebDAV collection that should be mounted by the client. 3.3. dm:open The optional <dm:open> element instructs the client to display the specified child collection; its URL is computed by concatenating this element's value with the URL obtained from the <dm:url> (Section 3.2) element (see Section 7 for a discussion about why this element only supports displaying collections rather than opening arbitrary documents). 3.4. dm:username The server can use the optional <dm:username> element to specify the name of the currently authenticated principal. A client can use this value to select a matching mount point (different users may have mounted the URL with different credentials under different local mount points) or to provide a meaningful default for authentication against the server. It is common that a browser and WebDAV client do not share HTTP connections, so including this information in the mount document increases usability. Implementation Note: If a <dm:username> element is present, public caching of the document should be disallowed. Thus, appropriate 'Vary' or 'Cache-Control' headers are needed in the server response. Reschke Informational [Page 5]

4. Example In the example below, the client first retrieves a representation of a WebDAV collection using a generic Web browser (1). The returned HTML content contains a hyperlink that identifies the "davmount" document in the format defined in Section 3 (2). The user follows this link (3), which causes the server to return the "davmount" document to the user's browser (4). The browser in turn passes the content to the application that was registered to handle the "application/davmount+xml" MIME type, usually the default WebDAV client on the client's system. (1) Client retrieves representation of WebDAV collection "/user42/inbox/". GET /user42/inbox/ HTTP/1.1 Host: www.example.com (2) Server returns representation. HTTP/1.1 200 OK Content-Type: text/html Content-Length: xxx.. <a href="?action=davmount">view this collection in your WebDAV client</a>.. (note that the example shows only that part of the HTML page that contains the relevant link) (3) Client follows link to "davmount" document GET /user42/inbox/?action=davmount HTTP/1.1 Host: www.example.com (4) Server returns "davmount" document HTTP/1.1 200 OK Content-Type: application/davmount+xml Content-Length: xxx Cache-Control: private <dm:mount xmlns:dm="http://purl.org/net/webdav/mount"> <dm:url>http://www.example.com/user42/</dm:url> <dm:open>inbox/</dm:open> </dm:mount> Reschke Informational [Page 6]

5. Internationalization Considerations This document does not introduce any new internationalization considerations beyond those discussed in [RFC2518], Section 16. Reschke Informational [Page 7]

6. IANA Considerations 6.1. MIME Type Registration Type name: application Subtype name: davmount+xml Required parameters: none Optional parameters: "charset": This parameter has identical semantics to the charset parameter of the "application/xml" media type as specified in [RFC3023]. Encoding considerations: Identical to those of "application/xml" as described in [RFC3023], Section 3.2. Security considerations: As defined in this specification. In addition, as this media type uses the "+xml" convention, it shares the same security considerations as described in [RFC3023], Section 10. Interoperability considerations: There are no known interoperability issues. Published specification: This specification. Applications that use this media type: SAP Netweaver Knowledge Management, Xythos Drive. Additional information: Magic number(s): As specified for "application/xml" in [RFC3023], Section 3.2. File extension(s):.davmount Fragment identifiers: As specified for "application/xml" in [RFC3023], Section 5. Base URI: As specified in [RFC3023], Section 6. Macintosh file type code(s): TEXT Person & email address to contact for further information: Julian Reschke <julian.reschke@greenbytes.de> Intended usage: COMMON Restrictions on usage: None. Author: Julian Reschke Reschke Informational [Page 8]

Change controller: IESG Reschke Informational [Page 9]

7. Security Considerations All security considerations connected to HTTP/WebDAV and XML apply for this specification as well, namely, [RFC2518] (Section 17) and [RFC3470] (Section 7). In addition, client implementers must be careful when implementing the <dm:open> element (see Section 3.3). It MUST NOT be used to initiate any action beyond displaying the contents of a WebDAV collection (supporting "opening" documents could be abused to trick a user into letting the operating system's shell execute arbitrary content, possibly running it as an executable program). The OPTIONAL <dm:username> element defined in Section 3.4 allows the inclusion of user names into mount documents. However in some cases, user name information is considered to be security sensitive. Should this be the case, parties generating mount documents are advised to either not to include user names, or to use access control to restrict access to the information as desired. Reschke Informational [Page 10]

8. Acknowledgements This document has benefited from thoughtful discussion by Emile Baizel, Spencer Dawkins, Lisa Dusseault, Stefan Eissing, Joe Gregorio, Michal Gregr, Russ Housley, Jim Luther, Jaroslav Mazanec, and Jim Whitehead. Reschke Informational [Page 11]

9. References 9.1. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. [RFC2518] [RFC2616] Goland, Y., Whitehead, E., Faizi, A., Carter, S., and D. Jensen, "HTTP Extensions for Distributed Authoring -- WEBDAV", RFC 2518, February 1999. Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P., and T. Berners-Lee, "Hypertext Transfer Protocol -- HTTP/1.1", RFC 2616, June 1999. [RFC3023] Murata, M., St.Laurent, S., and D. Kohn, "XML Media Types", RFC 3023, January 2001. [RFC3986] [XML] Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, January 2005. Bray, T., Paoli, J., Sperberg-McQueen, C., Maler, E., and F. Yergeau, "Extensible Markup Language (XML) 1.0 (Fourth Edition)", W3C REC-xml-20060816, August 2006, <http://www.w3.org/tr/2006 /REC-xml-20060816>. 9.2. Informative References [RFC3470] Hollenbeck, S., Rose, M., and L. Masinter, "Guidelines for the Use of Extensible Markup Language (XML) within IETF Protocols", RFC 3470, BCP 70, January 2003. [WEBARCH]Walsh, N. and I. Jacobs, "Architecture of the World Wide Web, Volume One", W3C RECwebarch-20041215, December 2004, <http://www.w3.org/tr/2004/rec-webarch-20041215/>. Reschke Informational [Page 12]

A. Alternative Approaches A.1....Through HTML/CSS Extensions Microsoft Internet Explorer implements a Cascading Style Sheet (CSS) extension that allows switching to its own WebDAV client ("Webfolder", see <http://msdn.microsoft.com/workshop/author/behaviors/reference/beh aviors/anchor.asp>). However, at the time of this writing, this extension was not implemented by any other user agent. A.2....Through Custom URI Schemes The "kio" library of the "K Desktop Enviroment" (<http://www.kde.org/>) uses the URI scheme "webdav" to dispatch to the system's WebDAV client. This URI scheme is not registered, nor is it supported on other platforms. Furthermore, the W3C's "Architecture of the World Wide Web, Volume One" explicitly advises against defining new schemes when existing schemes can be used: A specification SHOULD reuse an existing URI scheme (rather than create a new one) when it provides the desired properties of identifiers and their relation to resources. (See [WEBARCH], Section 2.4.) Reschke Informational [Page 13]

B. Implementations B.1. Example Implementation for Webfolder Client The figure below shows a sample implementation of a dispatcher for the application/davmount+xml datatype, suited for Win32 systems and the Microsoft "Webfolder" client. Reschke Informational [Page 14]

// sample implementation of application/davmount+xml // dispatcher for Windows Webfolder client // // to install/uninstall: // wscript davmount.js // // to open the webfolder: // wscript davmount.js filename // (where filename refers to an XML document with MIME type // application/davmount+xml) var EXTENSION = ".davmount"; var MIMETYPE = "application/davmount+xml"; var REGKW = "WebDAV.mount"; var NS = "xmlns:m='http://purl.org/net/webdav/mount"; // remove keys/entries from the registry function regdel(shell, key) { try { var x = shell.regread(key); try { shell.regdelete(key); } catch(e) { WScript.Echo("Error removing key " + key + ": " + e); } } catch(e) { // entry not present } } // methods for registering/unregistering the handler function install() { var WshShell = new ActiveXObject("WScript.Shell"); if (WshShell == null) { WScript.Echo("Couldn't instantiate WScript.Shell object"); return 2; } var fso = new ActiveXObject("Scripting.FileSystemObject"); var RegExt = "HKCR\\" + EXTENSION + "\\"; var RegMimeType = "HKCR\\MIME\\DataBase\\Content Type\\" + MIMETYPE + "\\"; var RegKw = "HKCR\\" + REGKW + "\\"; var extension = null; try { extension = WshShell.RegRead(RegMimeType + "Extension"); } catch (e) { } Reschke Informational [Page 15] if (extension == null) {

B.2. Xythos The "Xythos Drive" WebDAV client for WebDAV supports this specification starting with version 4.4. Reschke Informational [Page 16]

Index A application/mount+xml Media Type 8 D dm:mount 5 dm:opent 5 dm:url 5 dm:username 5 M Media Type application/mount+xml 8 Reschke Informational [Page 17]

Author's Address Julian F. Reschke greenbytes GmbH Hafenweg 16 Muenster, NW 48155 Germany Phone: +49 251 2807760 Fax: +49 251 2807761 EMail: julian.reschke@greenbytes.de URI: http://greenbytes.de/tech/webdav/ Full Copyright Statement Copyright The Internet Society (2006). This document is subject to the rights, licenses and restrictions contained in BCP 78, and except as set forth therein, the authors retain all their rights. This document and the information contained herein are provided on an AS IS basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Intellectual Property The IETF takes no position regarding the validity or scope of any Intellectual Property Rights or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; nor does it represent that it has made any independent effort to identify any such rights. Information on the procedures with respect to rights in RFC documents can be found in BCP 78 and BCP 79. Copies of IPR disclosures made to the IETF Secretariat and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementers or users of this specification can be obtained from the IETF on-line IPR repository at http://www.ietf.org/ipr 1. The IETF invites any interested party to bring to its attention any copyrights, patents or patent applications, or other proprietary rights that may cover technology that may be required to implement this standard. Please address the information to the IETF at ietf-ipr@ietf.org 2. Acknowledgment Funding for the RFC Editor function is provided by the IETF Administrative Support Activity (IASA). 1 http://www.ietf.org/ipr 2 mailto:ietf-ipr@ietf.org