view Side-By-Side changes
Network Working Group J. Gregorio, Ed. Internet-Draft BitWorking, Inc Expires: April14,30, 2006 B. de hOra, Ed. Propylon Ltd. October11,27, 2005 The Atom Publishing Protocoldraft-ietf-atompub-protocol-05.txtdraft-ietf-atompub-protocol-06.txt Status of this Memo By submitting this Internet-Draft, each author represents that any applicable patent or other IPR claims of which he or she is aware have been or will be disclosed, and any of which he or she becomes aware will be disclosed, in accordance with Section 6 of BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF), its areas, and its working groups. Note that other groups may also distribute working documents as Internet- Drafts. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." The list of current Internet-Drafts can be accessed at http://www.ietf.org/ietf/1id-abstracts.txt. The list of Internet-Draft Shadow Directories can be accessed at http://www.ietf.org/shadow.html. This Internet-Draft will expire on April14,30, 2006. Copyright Notice Copyright (C) The Internet Society (2005). AbstractThis memo presents a protocol for using XML (Extensible Markup Language) and HTTP (HyperText Transport Protocol) to edit content.The Atom Publishing Protocol (APP) is an application-level protocol for publishing and editing Web resources. The protocolat its coreisthebased on HTTP transport of Atom-formatted representations. The Atom format is documented in the Atom Syndication Format (draft-ietf-atompub-format-11.txt). Editorial Note Gregorio & de hOra Expires April14,30, 2006 [Page 1] Internet-Draft The Atom Publishing Protocol October 2005(draft-ietf-atompub-format-11.txt). Editorial NoteTo provide feedback on this Internet-Draft, join the atom-protocol mailing list (http://www.imc.org/atom-protocol/index.html) [1]. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 4 2.XML Namespace and LanguageNotational Conventions . . . . . . . . . . . . . . . . . . . 5 3.Notational ConventionsTerminology . . . . . . . . . . . . . . . . . . . . . . . . 6 4.Terminology .Protocol Model . . . . . . . . . . . . . . . . . . . . . . . 7 5.The Atom PublishingProtocolModelOperations . . . . . . . . . . . . .8 5.1 Collections. . . . . . . 8 5.1 Retrieving an Introspection Document . . . . . . . . . . . 8 5.2 Creating a Resource . . . . .8 5.2 Editable Resources. . . . . . . . . . . . . . 8 5.3 Editing a Resource . . . . . .9 5.2.1 Read. . . . . . . . . . . . . . 8 5.3.1 Retrieving a Resource . . . . . . . . . . .10 5.2.2 Update. . . . . 9 5.3.2 Updating a Resource . . . . . . . . . . . . . . . . . 9 5.3.3 Deleting a Resource . .10 5.2.3 Delete. . . . . . . . . . . . . . . 9 5.4 Listing Collections . . . . . . . . .10 5.3 Capabilities Discovery. . . . . . . . . . 10 5.5 Success and Failure . . . . . . . .11 5.4 Listing. . . . . . . . . . . 10 6. XML-related Conventions . . . . . . . . . . . . . .11 5.5 Success and Failure. . . . 11 6.1 Referring to Information Items . . . . . . . . . . . . . . 11 6.2 XML Namespace Usage . .12 6. Atom Publishing Protocol Documents. . . . . . . . . . . . .13 6.1 Use of xml:base xml:lang. . . . 11 6.3 RELAX NG Schema . . . . . . . . . . . . .13 6.2 Collection Documents. . . . . . . . 11 6.4 Use of xml:base and xml:lang . . . . . . . . . . .14 6.2.1 Element Definitions. . . . 11 7. Introspection Documents . . . . . . . . . . . . .14 6.3 Introspection Documents. . . . . 13 7.1 Introduction . . . . . . . . . . . .16 6.3.1 Element Definitions. . . . . . . . . . . 13 7.2 Example . . . . . .17 7. Introspection Resource. . . . . . . . . . . . . . . . . . .20 7.1 Discovery13 7.3 Element Definitions . . . . . . . . . . . . . . . . . . . 14 7.3.1 The 'app:service' Element . . . . .20 8. Collection Resources. . . . . . . . . 14 7.3.2 The 'app:workspace' Element . . . . . . . . . . .21 8.1 GET. . 14 7.3.3 The 'app:collection' Element . . . . . . . . . . . . . 15 7.3.4 The 'app:member-type' Element . . . . . . . . . . . .21 8.2 POST15 7.3.5 The 'app:list-template' Element . . . . . . . . . . . 16 8. Collections . . . . . . . . . . . . . . . .21 8.3 Title: Header. . . . . . . . 18 8.1 Creating resources with POST . . . . . . . . . . . . . .22 9. Entry Collections. 18 8.1.1 Title: Header . . . . . . . . . . . . . . . . . . . .23 9.1 Editing18 8.2 EntryResourcesCollections . . . . . . . . . . . . . . . . .23 9.2. . . 19 8.2.1 Role of Atom Entry Elements During Editing . . . . . .. . 23 10. Generic19 8.3 Media Collections . . . . . . . . . . . . . . . . . . . .25 10.120 8.3.1 EditingGenericMedia Resources . . . . . . . . . . . . . . .25 10.2 Title: Header . . . .20 9. Listing Collections . . . . . . . . . . . . . . . . .25 11. List Resources. . . 21 10. Atom Entry Extensions . . . . . . . . . . . . . . . . . . .. 26 11.1 URI Templates . . . . . . . . .23 10.1 The 'edit' Link Relation . . . . . . . . . . . .26 11.2 URI Template Parameters. . . . 23 10.2 Publishing Control . . . . . . . . . . . .27 11.2.1 \{index\} URI template variable. . . . . . . 23 10.2.1 The app:draft Element . . .27 11.2.2 \{daterange\} URI template variable. . . . . . . .27 11.2.3 Other URI Template parameters. . . . 24 11. Example . . . . . . .28 12. Atom Entry Extensions. . . . . . . . . . . . . . . . . . .29 13.25 12. Securing the Atom Protocol . . . . . . . . . . . . . . . . .30 Gregorio & de hOra Expires April 14, 2006 [Page 2] Internet-Draft The Atom Publishing Protocol October 2005 14.27 13. Security Considerations . . . . . . . . . . . . . . . . . .31 15.28 14. IANA Considerations . . . . . . . . . . . . . . . . . . . .32 16.29 Gregorio & de hOra Expires April 30, 2006 [Page 2] Internet-Draft The Atom Publishing Protocol October 2005 15. References . . . . . . . . . . . . . . . . . . . . . . . . .35 16.131 15.1 Normative References . . . . . . . . . . . . . . . . . .35 16.231 15.2 Informative References . . . . . . . . . . . . . . . . .3632 Authors' Addresses . . . . . . . . . . . . . . . . . . . . .3733 A. Contributors . . . . . . . . . . . . . . . . . . . . . . . .3834 B. RELAX NG Compact Schema . . . . . . . . . . . . . . . . . . 35 C. Revision History . . . . . . . . . . . . . . . . . . . . . .3938 Intellectual Property and Copyright Statements . . . . . . .4140 Gregorio & de hOra Expires April14,30, 2006 [Page 3] Internet-Draft The Atom Publishing Protocol October 2005 1. Introduction The Atom Publishing Protocol is an application-level protocol for publishing and editing Web resources using HTTP [RFC2616] and XML 1.0 [W3C.REC-xml-20040204].Gregorio & de hOra Expires April 14, 2006 [Page 4] Internet-Draft The Atom Publishing Protocol October 2005 2. XML Namespace and Language The XML Namespaces URI [W3C.REC-xml-names-19990114] for the XML data format described in this specification is: http://purl.org/atom/app# XML elements defined by this specification MAY have an xml:lang attribute, whose content indicates the natural language for the element (and its descendents).Thelanguage context is only significant for elements and attributes declared to be "Language- Sensitive" by this specification. Requirements regardingprotocol supports thecontentcreation of arbitrary web resources andinterpretationprovides facilities for: o Collections: Sets ofxml:lang are specifiedresources, which may be retrieved in[W3C.REC-xml- 20040204], Section 2.12.whole or in part. o Introspection: Discovering and describing collections. o Editing: Creating, updating and deleting resources. Gregorio & de hOra Expires April14,30, 2006 [Page5]4] Internet-Draft The Atom Publishing Protocol October 20053.2. Notational Conventions The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].Some sections of this specification are illustrated with fragments of a non-normative RELAX NG Compact schema [RNC]. However,Note: The Introspection Document allows thetextuse ofthis specification provides the definition of conformance. This specification uses the namespace prefix "app:" for the NamespaceIRIs [RFC3987], as well as URIs [RFC3986]. Every URIidentified in Section 2 above. It uses the namespace prefix "atom:" for the Namespaceis an IRI, so any URIidentifiedcan be used where an IRI is needed. How to map an IRI to a URI is specified in[AtomFormat]. Note that choicesSection 3.1 ofnamespace prefix are arbitrary and not semantically significant.Internationalized Resource Identifiers (IRIs) [RFC3987]. Gregorio & de hOra Expires April14,30, 2006 [Page6]5] Internet-Draft The Atom Publishing Protocol October 20054.3. Terminology For convenience, this protocol may be referred to as "Atom Protocol" or "APP".ThisThe phrase "the IRI of a document" in this specificationuses both internally.is shorthand for "an IRI which, when dereferenced, is expected to produce that document as a representation". URI/IRI - A Uniform Resource Identifier and Internationalized Resource Identifier, respectively. These terms (and the distinction between them) are defined in [RFC3986] and [RFC3987].Resourceresource - A network data object or service that can be identified by aURI,IRI, as defined in [RFC2616].RepresentationSee [W3C.REC-webarch-20041215] for further discussion on resources. representation - An entity included with a request or response as defined in [RFC2616]. collection - A resource that contains a set of member IRIs, as described in Section 8 of this specification. member - A resource whose IRI is listed in a collection. IRI template - A parameterized string that becomes a IRI when the parameters are filled in. See Section 9. introspection document - A document that describes the location and capabilities of one or more collections. See Section 7 client writable element - An element of an Atom Entry whose value is editable by the client and not enforced by the server. server-controlled element - An element of an Atom Entry whose value is enforced by the server and not editable by the client. Gregorio & de hOra Expires April14,30, 2006 [Page7]6] Internet-Draft The Atom Publishing Protocol October 20055. The Atom Publishing4. Protocol Model The Atom Publishing Protocolis a subset ofuses HTTPthat is usedto edit resources on the web.The APP operates onIt provides a list based mechanism for managing collections ofWebeditable resources called member resources. Collectionsare HTTP resources, as are the members ofcontain thecollection. Both CollectionsIRIs andcollectionmetadata describing memberresources support the same basic interactions.resources. Thepatterns of interaction are based on the commonAPP uses these HTTPverbs.verbs: o GET is used to retrieve a representation of a resource or perform aread-onlyquery. o POST is used to create a new, dynamically-namedresource, or to provide a block of data to a data-handling process.resource. o PUT is used to update a known resource. o DELETE is used to remove a resource.5.1 Collections The APP groups resources into "Collections", which are analogous to folders or directories found in a file system. InThis diagram shows thefigure we have member resources in a collection. +-------------------------+ | Collection | | | | +----------------+ | | | Member_A | | | +----------------+ | | | | +----------------+ | | | Member_BAPP model: +---------------+ | Introspection | +------------+ |+----------------+|-->| Collection | +---------------+ | | |+----------------+| +--------+ | |-->| Member |Member_C| | +--------+ |+----------------+| | | . |...| . | | . |+----------------+| | |Member_Oldest+--------+ | |-->| Member | |+----------------+| +--------+ | |+-------------------------++------------+ The introspection document contains the IRIs of one or more collections. A collection contains IRIs and metadata describing member resources. The protocol allows editing of resources with representations of any media-type. Some types of collections are specialized and restrict the resource representations of their members. Gregorio & de hOra Expires April14,30, 2006 [Page8]7] Internet-Draft The Atom Publishing Protocol October 2005To add a new member to a collection5. Protocol Operations 5.1 Retrieving anappropriate representation is POSTedIntrospection Document Client Server | | | 1.) GET tothe URIIRI ofthe collection resource. Here we show it being addedIntrospection Document | |------------------------------------------>| | | | 2.) Introspection Document | |<------------------------------------------| | | 1. The client sends a GET request to thebeginnngIRI of thelist.introspection document. 2. Theordering of the members of collections is in terms ofserver responds with thetime at which each resource was last updated,introspection document whichincludesenumerates theactIRIs ofcreatingall theresource. The ordering of collection members is covered in more detail in Section 8collections, andSection 11. +-------------------------+ | Collectionthe capabilities of those collections, that the service supports. 5.2 Creating a Resource Client Server | | | 1.) POST to IRI of Collection |+----------------+ | --------->| Member_New | ||------------------------------------------>| |+----------------+| | 2.) 201 Created | |<------------------------------------------| |+----------------+|| | Member_A | | | +----------------+ | | | | +----------------+ | | | Member_B | | | +----------------+ | | | | +----------------+ | | | Member_C | | | +----------------+ | | | | ... | | | | +----------------+ | | | Member_Oldest | | | +----------------+ | | | +-------------------------+ You'll note that up until now we haven't said what kinds of representations we are expecting at each of1. The client POSTs a representation to theresources. There are two kindsIRI ofcollections, Entry and Generic. In Entry Collections allthemembers MUST have representations as Atom Entries. For further restrictions on Entry Collection see Section 9 The other typecollection. 2. If the member resource was created successfully the server responds with a status code ofcollection is201 and aGeneric Collection. Generic Collections make no restriction onLocation: header that contains therepresentationsIRI oftheir member resources. 5.2 Editable Resources Allthemembers ofnewly created member resource. 5.3 Editing acollection are Editable Resources. An Editable resource isResource Once a resourcewhose available HTTP methods canhas been created and its IRI is known, that IRI may be used to retrieve,updateupdate, and delete it. Gregorio & de hOra Expires April14,30, 2006 [Page9]8] Internet-Draft The Atom Publishing Protocol October 20055.2.1 Read To retrieve a representation of the resource, you send5.3.1 Retrieving aGET to the URI of the Editable Resource. Remember that for members of Entry Collections, the served representation will be an Atom Entry.Resource Client Server | | | 1.) GET toEditable Resource URIMember IRI | |------------------------------------------>| | | | 2.)200 OKMember Representation | |<------------------------------------------| | | 1. The client sends a GET request to the member'sURI.IRI to retrieve its representation . 2. The server responds with the representation of the resource.5.2.2 Update To update an Editable5.3.2 Updating a Resourcethe client will PUT an updated representation to the URI of the resource.Client Server | | | 1.) PUT toEditable Resource URIMember IRI | |------------------------------------------>| | | | 2.) 200 OK | |<------------------------------------------| 1. The client PUTs an updated representation to the member'sURI.IRI. 2.TheUpon a successful update of the resource the serverMAY respondresponds withan updated representationa status code ofthe member's new state. 5.2.3 Delete An Editable200. 5.3.3 Deleting a Resourceis deleted by sending it DELETE. Note that this also removes it from all the collections that it belonged to. Gregorio & de hOra Expires April 14, 2006 [Page 10] Internet-Draft The Atom Publishing Protocol October 2005Client Server | | | 1.) DELETE toEditableMember ResourceURIIRI | |------------------------------------------>| | | | 2.) 200 Ok | |<------------------------------------------| | | 1. The client sends a DELETE request to the member'sURI.IRI. 2.The server responds withUpon the successfulstatus code. 5.3 Capabilities Discovery Each collectiondeletion of the resource the server respondsto GET and can returnwith aCollection Document as it's representation.status code of 200. Gregorio & de hOra Expires April 30, 2006 [Page 9] Internet-Draft TheCollection Document enumeratesAtom Publishing Protocol October 2005 Note: deleting a member also removes it from all thecapabilitiescollections to which it belongs. 5.4 Listing Collections To enumerate the members ofeacha collectionandtheformatclient sends a GET to its IRI. This IRI isdescribedconstructed from information in the introspection document. An Atom Feed Document is returned with one Atom Entry for each member resource that matches the selection criteria in the IRI. See Section 9 and Section6.2.10 for a description of the feed contents. Client Server | | | 1.) GET toCollectionList IRI | |------------------------------->| | | | 2.)Collection Document200 OK, Atom Feed Doc | |<-------------------------------| | | 1. The client sends a GET request to theCollection Resource.membership list IRI. 2. The server responds witha Collectionan Atom Feed Document containinga description ofthecapabilitiesIRIs of all thecollection.collection members that match the selection criteria. 5.5 Success and Failure Thecontent of this document can vary based on aspects ofAtom Protocol uses HTTP status codes to signal theclient request, including, but not limited to, authentication credentials. 5.4 Listing Clients can request a listingresults of protocol operations. Status codes of theCollection's membership. Listing the Editable Resourcesform 2xx signal thatare members ofacollection is done using onerequest was successful. HTTP status codes of theList Resources inform 4xx or 5xx signal that an error has occurred. Consult theIntrospection Document, utilizingHTTP specification [RFC2616] for the'app:uri-template' element. The List Resource returns Atom Feed Documents with one Atom Entry for each member resource that match the selection criteria. This is true whether the collection is an Entry Collection or a Generic Collection. If an Entry Collection is being interrogated, the entries returned by a list resource SHOULDdefinitions of HTTP status codes. Gregorio & de hOra Expires April14,30, 2006 [Page11]10] Internet-Draft The Atom Publishing Protocol October 2005NOT to be considered complete representations6. XML-related Conventions The data format in this specification is specified in terms of themember resources. See Section 11XML Information Set, serialised as XML 1.0 [W3C.REC-xml-20040204]. Atom Publishing Protocol Documents MUST be well-formed XML. This specification does not define any DTDs for Atom Protocol, andSection 12hence does not require them to be valid (in the sense used by XML). 6.1 Referring to Information Items This specification uses a shorthand formore details ontwo common terms: theextensionsphrase "Information Item" is omitted when naming Element Information Items andconstraints found onAttribute Information Items. Therefore, when this specification uses theentries returned from List Resources. Client Server | | | 1.) GETterm "element," it is referring toList Resource | |------------------------------->| | | | 2.) 200 OK, Atom Feed Doc | |<-------------------------------| | | 1. The client sends a GET requestan Element Information Item in Infoset terms. Likewise, when it uses the term "attribute," it is referring to an Attribute Information Item. 6.2 XML Namespace Usage The Namespace URI [W3C.REC-xml-names-19990114] for the data format described in this specification is: http://purl.org/atom/app# This specification uses the prefix "app:" for theCollection'sNamespace URI.2.Theserver responds with an Atom Feed Document containing a full or partial listingchoice of namespace prefix is not semantically significant. This specification also uses theCollection's membership. 5.5 Success and Failure HTTP defines different classesprefix "atom:" for the Namespace URI identified in [AtomFormat]. 6.3 RELAX NG Schema Some sections ofresponse, whichthis specification areused by the Atom Protocol. HTTP status codesillustrated with fragments ofthe form 2xx signal thatarequest was successful. HTTP status codesnon-normative RELAX NG Compact schema [RNC]. However, the text of this specification provides theform 4xx or 5xx signal that an error has occurred,definition of conformance. A complete schema appears in Appendix B. 6.4 Use of xml:base and xml:lang XML elements defined by this specification MAY have an xml:base attribute [W3C.REC-xmlbase-20010627]. When xml:base is used, it serves therequest has failed. Consultfunction described in section 5.1.1 of [RFC3986], establishing theHTTP specification [RFC2616]base URI (or IRI) formore detailed definitionsresolving any relative references found within the effective scope ofeach status code.the xml:base attribute. Any element defined by this specification MAY have an xml:lang attribute, whose content indicates the natural language for the Gregorio & de hOra Expires April14,30, 2006 [Page12]11] Internet-Draft The Atom Publishing Protocol October 20056. Atom Publishing Protocol Documents This specification describes two kindselement and its descendents. The language context is only significant for elements and attributes declared to be "Language- Sensitive" by this specification. Requirements regarding the content and interpretation of xml:lang are specified in Section 2.12 of XML 1.0 [W3C.REC-xml-20040204], . appCommonAttributes = attribute xml:base { atomUri }?, attribute xml:lang { atomLanguageTag }?, undefinedAttribute* Gregorio & de hOra Expires April 30, 2006 [Page 12] Internet-Draft The Atom Publishing ProtocolDocuments: Atom Collections Documents and AtomOctober 2005 7. IntrospectionDocuments. An Atom Collection Document isDocuments 7.1 Introduction For authoring to commence, arepresentation of an Atom collection, including metadata aboutclient needs to first discover thecollection,capabilities andsome or alllocations ofthe members associated with it. Its rootcollections offered. This isthe app:collection element.done using Introspection Documents. AnAtomIntrospection Documentrepresents one or moredescribes workspaces, whichdescribe server-defined groupings of collections. Its root is the app:service element. namespace app = "..." start = appCollection | appIntrospection Both kinds of Atom Publishing Protocol Documents are specified in terms of the XML Information Set, serialised as XML 1.0 ([W3C.REC- xml-20040204]). Atom Publishing Protocol Documents MUST be well- formed XML. This specification does not define a DTD for Atom Protocol, and hence does not require them to be valid (in the sense used by XML). Atom Collection Documents are identified with the "application/ atomcoll+xml" media type. Atom Introspection Documents are identified with the "application/ atomserv+xml" media type. Atom allows the use of IRIs [RFC3987], as well as URIs [RFC3986]. Every URI is an IRI, so any URI can be used where an IRI is needed. While IRIs must, for many protocols, be mapped to URIs prior to dereferencing, they MUST NOT be so mapped for comparison when used in atom:id. Section 3.1 of [RFC3987] describes how to map an IRI to a URI when necessary. 6.1 Use of xml:base xml:lang Any element defined by this specification MAY have an xml:base attribute [W3C.REC-xmlbase-20010627]. When xml:base is used in an Atom Publishing Protocol Document, it serves the function described in section 5.1.1 of [RFC3986], establishing the base URI (or IRI) for resolving any relative references found within the effective scope of the xml:base attribute. Any element defined by this specification MAY have an xml:lang attribute, whose content indicates the natural language for the Gregorio & de hOra Expires April 14, 2006 [Page 13] Internet-Draft The Atom Publishing Protocol October 2005 element and its descendents. The language context is only significant for elements and attributes declared to be "Language- Sensitive" by this specification. Requirements regarding the content and interpretation of xml:lang are specified in XML 1.0 ([W3C.REC- xml-20040204]), Section 2.12. appCommonAttributes = attribute xml:base { atomUri }?, attribute xml:lang { atomLanguageTag }?, undefinedAttribute* 6.2 Collection Documents The Collection Document describes the capabilities of a Collection, the types of Entries that it will support, the URI Templates it supports. The Collection Document has the media-type 'application/atomcoll+xml' (see Section 15). Here's an example document: <?xml version="1.0" encoding='utf-8'?> <app:collection xmlns:app="http://purl.org/atom/app#"> <app:member-type>entry</pub:member-type> <app:uri-template>http://example.org/{index}</pub:uri-template> <app:uri-template>http://example.org/{daterange}</pub:uri-template> </app:collection> This example says the Collection contains Atom Entry documents, and that there are two means of selecting entries using what are called 'URI Templates'; one based on the collection's order, and another based on dates. See Section 11.1 for more about URI Templates. 6.2.1 Element Definitions 6.2.1.1 The 'app:collection' Element The app:collection is the document element of a Collection Document. appCollection = element app:collection { appCommonAttributes, ( appMemberType+ appSearchTemplate & anyElement* ) Gregorio & de hOra Expires April 14, 2006 [Page 14] Internet-Draft The Atom Publishing Protocol October 2005 } This specification defines two child elements for app:collection: o app:member-type: any number of elements listing the types of Entries that the Collection may contain. o app:uri-template: any number of URI Templates for a List Resource (See Section 11). 6.2.1.2 The 'app:member-type' Element The app:member-type element contains information elements about the types of Entries that the Collection may contain. appMember = element app:member-type { appCommonAttributes, appTypeValue } The element content of an app:member-type MUST be a string that is non-empty, and matches either the "isegment-nz-nc" or the "IRI" production in [RFC3987]. Note that use of a relative reference other than a simple name is not allowed. If a name is given, implementations MUST consider the link relation type to be equivalent to the same name registered within the IANA Registry of Member Types (Section 15), and thus the IRI that would be obtained by appending the value of the rel attribute to the string "http://www.iana.org/assignments/entrytype/". The content of an app:member-type specifies constraints on the Entries that may appear in the Collection. The app:collection element MAY have multiple app:member-type elements. An Entry POSTed to a Collection MUST meet the constraints of at least one of the app: member-type constraints. It MAY meet more than one, but the minimum requirement is at least one. This specification defines two initial values for app:member-type IANA registry: o "entry" - The Collection is an Entry Collection as defined in Section 9. Gregorio & de hOra Expires April 14, 2006 [Page 15] Internet-Draft The Atom Publishing Protocol October 2005 o "generic" - The Collection is a Generic Collection as defined in Section 10. 6.2.1.3 The 'app:uri-template' Element The element content of an app:uri-template is a URI Template for a List Resource (See Section 11). Every List resource, whose URI is determined by filling in the parameters in a URI Template, MUST return an Atom feed document as its representation. This Atom feed document MUST NOT contain entries which do not match the selection criteria. 6.3 Introspection Documents In order for authoring to commence, a client must first discover the capabilities and locations of collections offered. The Introspection Document describes "workspaces", whichareserver- definedserver-defined groupings of collections.There is no requirement that servers support multiple workspaces, and a collection may appear in more than one workspace. The Introspection Document has the media-type 'application/ atomserv+xml', see Section 15 Here's an example document:7.2 Example <?xml version="1.0" encoding='utf-8'?><app:service xmlns:app="http://purl.org/atom/app#"> <app:workspace<service xmlns="http://purl.org/atom/app#"> <workspace title="Main Site" ><app:collection contents="entries"<collection title="My Blog Entries"href="http://example.org/reilly/feed" /> <app:collection contents="generic" title="Documents"href="http://example.org/reilly/main" > <member-type>entry</member-type> <list-template>http://example.org/{index}</list-template> </collection> <collection title="Pictures" href="http://example.org/reilly/pic"/> </app:workspace> <app:workspace> <member-type>media</member-type> <list-template>http://example.org/p/{index}</list-template> </collection> </workspace> <workspace title="Side Bar Blog"><app:collection contents="entries" title="Entries" href="http://example.org/reilly/feed" /> <app:collection contents="http://example.net/booklist" title="Books" href="http://example.org/reilly/books" /> </app:workspace> </app:service><collection title="Remaindered Links" href="http://example.org/reilly/list" > <member-type>entry</member-type> <list-template>http://example.org/l/{index}</list-template> </collection> </workspace> </service> Thisexample says there are two workspaces, each consisting ofIntrospection Document describes twoGregorio & de hOra Expires April 14, 2006 [Page 16] Internet-Draft The Atom Publishing Protocol October 2005 collections.workspaces. Thefirst workspace isfirst, called'Mail', and'Main Site', has twocollections,collections called 'My Blog Entries' and'Documents''Pictures' whoselocationsIRIs are'http://example.org/reilly/feed''http://example.org/reilly/main' and'http://example.org/reilly/pic'.'http://example.org/reilly/pic' respectively. 'My Blog Entries'contains Atom Entriesis an Entry collection and'Documents' contains Generic Entries.'Pictures' is a Media collection. Entry and Media collections are discussed in Section 7.3.4. The second workspace is called 'Side Bar Blog' andalsohastwo collections,a single collection called'Entries' and 'Books''Remaindered Links' whoselocations are 'http://example.org/reilly/feed' and 'http://example.org/reilly/booklist'. 'Entries' contains Atom Entries and 'Books' contains Generic Entries (since its contents attributecollection IRI isnot present you MUST assume it'http://example.org/reilly/list'. 'Remaindered Links' is an Entry collection. Gregorio & de hOra Expires April 30, 2006 [Page 13] Internet-Draft The Atom Publishing Protocol October 2005 Introspection documents are identified with the "application/ atomserv+xml" media type (see Section 14). While an introspection document allows multiple workspaces, there is no requirement that aGeneric Collection). 6.3.1service support multiple workspaces. In addition, a collection MAY appear in more than one workspace. 7.3 Element Definitions6.3.1.17.3.1 The 'app:service' Element The root of an introspection document is the app:service element. namespace app = "http://purl.org/atom/app#" start = appService The "app:service" element is thedocument element of a Introspection Document, acting as acontainer forservice dataintrospection information associated with one or more workspaces. An app:serviceelements MAYelement MUST containany number ofone or more app:workspace elements. appService = element app:service { appCommonAttributes, (appWorkspace*appWorkspace+ &anyElement*extensionElement* ) }6.3.1.27.3.2 The 'app:workspace' Element The'workspace''app:workspace' element contains information elements about the collections of resources available for editing. The app:workspaceelements MAYelement MUST containany number ofone or more app:collection elements. appWorkspace = element app:workspace { appCommonAttributes, attribute title { text }, (appCollection*appCollection+ &anyElement*extensionElement* ) }Gregorio & de hOra Expires April 14, 2006 [Page 17] Internet-Draft The Atom Publishing Protocol October 2005 6.3.1.2.17.3.2.1 The 'title' Attribute The app:workspace element MUST contain a 'title' attribute, which conveys a human-readable name for the workspace. This attribute is Gregorio & de hOra Expires April 30, 2006 [Page 14] Internet-Draft The Atom Publishing Protocol October 2005 Language-Sensitive.6.3.1.37.3.3 The 'app:collection' Element The'app:collection' element describes collectionsapp:collection contains information elements that describe the location andtheir member resources.capabilities of a collection. appCollection = element app:collection { appCommonAttributes, attribute title { text }, attribute href { text },attribute contents { text }, anyElement*( appMemberType & appListTemplate & extensionElement* ) }6.3.1.3.17.3.3.1 The 'title' Attribute The app:collection element MUST contain a 'title' attribute, whose value conveys a human-readable name for theworkspace.collection. This attribute is Language-Sensitive.6.3.1.3.27.3.3.2 The 'href' Attribute The app:collection element MUST contain an 'href' attribute, whose value conveys the IRI of the collection.6.3.1.3.3 The 'contents' Attribute The app:collection element MAY contain a 'contents' attribute. The 'contents' attribute conveys the nature of a collection's member resources.This specification defines twoinitial valueschild elements forthe 'contents' attribute:app:collection: o'entry': A value of 'entry' for the contents attribute indicatesapp:member-type: a single element that contains theCollection is an Entry Collection (Section 9). o 'generic': A valuetype of'generic' for the contents attribute indicatesmembers that theCollection iscollection can contain. o app:list-template: aGeneric Collection (Section 10). If the attribute is not present, its valuesingle element that contains a IRI template of a membership list. (See Section 9). 7.3.4 The 'app:member-type' Element The app:collection element MUSTbe considered to be Gregorio & de hOra Expires April 14, 2006 [Page 18] Internet-Draftcontain one 'app:member-type' element. TheAtom Publishing Protocol October 2005 'generic'.app:member-type element value specifies the types of members that can appear in the collection. Gregorio & de hOra Expires April14,30, 2006 [Page19]15] Internet-Draft The Atom Publishing Protocol October 20057. Introspection Resource To retrieveappMemberType = element app:member-type { appCommonAttributes, ( appTypeValue ) } appTypeValue = "entry" | "media" An Entry POSTed to a collection MUST meet the constraints of the app: member-type element. This specification defines two initial values for the app:member-type IANA registry: o "entry" - The collection contains only member resources whose representation MUST be anIntrospection Document,Atom Entry. Further constraints on theclient sendsrepresentations of members in aGET request to its URI. GET /service-desc HTTP/1.1 Host: example.org User-Agent: Cosimo/1.0 Accept: application/atomserv+xmlcollection of type "entry" are listed in Section 8.2. o "media" - Theserver responds to a GET request by returning an Introspection Documentcollection contains member resources whose representation can be of any media type. Additional constraints are listed in Section 8.3. In general themessage body. HTTP/1.1 200 OK Date: Mon, 21 Mar 2005 19:20:19 GMT Server: CountBasic/2.0 Last-Modified: Mon, 21 Mar 2005 19:17:26 GMT ETag: "4c083-268-423f1dc6" Content-Length: nnnn Content-Type: application/atomserv+xml <?xml version="1.0" encoding='utf-8'?> <app:service xmlns:app="http://purl.org/atom/app#"> ... </app:service> 7.1 Discovery [[anchor18: Addvalue of app:member-type MUST be a string that is non- empty, and matches either the "isegment-nz-nc" or the "IRI" production indesc[RFC3987]. Note that use ofan HTMLa relative reference other than a simple name is not allowed. If a name is given, implementations MUST consider the linkelement that pointsrelation type to be equivalent to theIntrospection Resource, or add itsame name registered within the IANA Registry of Link Relations Section 14, and thus the IRI that would be obtained by appending the value of the rel attribute to theautodisco draft]]string "http://www.iana.org/assignments/member-type/". 7.3.5 The 'app:list-template' Element The app:collection element MUST contain one 'app:list-template' elements. The element content of app:list-template is an IRI template (Section 9) for a collection. appListTemplate = element app:list-template { appCommonAttributes, ( appUriTemplate ) } appUriTemplate = xsd:string { pattern = ".+\{.+\}.*" } Gregorio & de hOra Expires April14,30, 2006 [Page20]16] Internet-Draft The Atom Publishing Protocol October 20058. Collection Resources AnGregorio & de hOra Expires April 30, 2006 [Page 17] Internet-Draft The AtomCollection is a set of related resources. All members of a collection have an "app:updated" property, and the Collection is considered to be ordered by this property. This specification defines two HTTP methods for use with collection resources: GET and POST.Publishing Protocol October 2005 8. Collections 8.1GET A GET to a Collection Resource returns a Collection Document, outlining the Collection. Collection Documents are described in Section 6.2. 8.2Creating resources with POSTIn addition to GET, a Collection Resource alsoEvery collection accepts POSTrequests. Therequests to create resources - the client POSTs a representation of the desired resource to theCollection Resource. Note that some collections mayIRI of the collection. Collections MAY impose constraints on themedia-typesmedia- types that are created in aCollectioncollection and MAY generate a response with a status code of 415 ("Unsupported Media Type").In the case of a successful creation, theThe status code returned for a successful creation POST MUST be 201 ("Created").EveryA successful creation POST MUST return a Location: header with the URI of the newly created resource.Here's an example.Clients MAY POST invalid Atom for initial resource creation - specifically the id and link elements MAY be omitted. Below, the client requests to create a resource in aCollection: Gregorio & de hOra Expires April 14, 2006 [Page 21] Internet-Draft The Atom Publishing Protocol October 2005collection: POST /edit HTTP/1.1 Host: example.org User-Agent:Cosimo/1.0 Accept: application/atom+xmlThingio/1.0 Content-Type: application/atom+xml Content-Length:601 <atom:entry xmlns:atom="http://www.w3.org/2005/Atom"> <atom:title>Mars Attacks!</atom:title> <atom:summary type="html"> Why cant we all just... get along? </atom:summary> <atom:author> <atom:name>The President</atom:name> <atom:uri>http://www.example.org/blog</atom:uri> </atom:author> <atom:content type="html" xml:lang="en" xml:base="http://www.example.org/blog/"> <p> Why can't we...work out our differences? Why can't we...work things out? Little people...why can't we all just...get along? </p> </atom:content> </atom:entry>nnn <entry xmlns="http://www.w3.org/2005/Atom"> <title>Atom-Powered Robots Run Amok</title> <updated>2003-12-13T18:30:02Z</updated> <summary>Some text.</summary> </entry> The resource is created by sending an Atom Entry as the entity body.Assuming the server created the resource successfully, it sends backSuccessful creation is indicated by a 201Createdcreated responsewithand includes a Location:header that contains the IRI of the newly created member as an Editable Resource.header. HTTP/1.1 201 Created Date: Fri, 7 Oct 2005 17:17:11 GMT Content-Length:663 Content-Type: application/atom+xml; charset="utf-8"0 Location: http://example.org/edit/first-post.atom8.38.1.1 Title: Header The POST to aCollection Resourcecollection MAY contain a Title: header that indicates theclientsclient's suggestednametitle for the resource. The server MAY ignore the Title: header or modify the requestedname to suit local conventions. Title = "Title" ":" [text]title. Gregorio & de hOra Expires April14,30, 2006 [Page22]18] Internet-Draft The Atom Publishing Protocol October 20059.Title = "Title" ":" [text] The syntax of this header MUST conform to the augmented BNF grammar in section 2.1 of the HTTP/1.1 specification [RFC2616]. 8.2 Entry Collections Entry Collections areCollectionscollections that restrict their membership to Atomentries. 9.1 Editing Entry Resources Atom entriesEntries. They areeditedidentified bysending HTTP requests tohaving an app:member-type of "entry". Every member representation MUST contain anindividual entry's URI. Servers can determine the processing necessary to interpretatom:link element with arequest by examiningrelation of rel="edit" that contains therequest's HTTP method and 'Content-Type' header. Processing Client Requests +-----------+------+--------+--------+------+ | | GET | PUT | DELETE | POST | +-----------+------+--------+--------+------+ | No Body | Read | x | Delete | x | | | | | | | | Atom Body | x | Update | x | x | +-----------+------+--------+--------+------+ 9.2IRI of the member resource. Member representations MAY contain an app:control element (Section 10.2). 8.2.1 Role of Atom Entry Elements During Editing The elements of an Atom Entry Document are either a'Writable Element'client writable ora 'Round Trip Element'.server controlled. Client WritableElement- An element of an Atom Entry whose value is editable by the client. Servers MAY modify the content of clientand not enforced bywritable elements. Some reasons that a server may change client writable content include length limits, obscenity filters or theserver. Round Trip Elementaddition of boilerplate text. Server Controlled - An element of an Atom Entry whose value is enforced by the server and not editable by the client.That categorization will determineClients SHOULD NOT change theelements' disposition during editing.value of server controlled elements. Servers MUST NOT rely on clients preserving the values of server controlled elements. Gregorio & de hOra Expires April14,30, 2006 [Page23]19] Internet-Draft The Atom Publishing Protocol October 2005+--------------------+------------++--------------------+--------------------+ | Atom Entry Element | Property |+--------------------+------------++--------------------+--------------------+ | atom:author | Client Writable | | | | | atom:category | Client Writable | | | | | atom:content | Client Writable || | | | atom:contributor | Writable | | | | | atom:id | Round Trip | | | | | atom:link | Writable | | | | | atom:published | Writable | | | | | atom:source | Writable | | | | | atom:summary | Writable | | | | | atom:title | Writable | | | | | atom:updated | Round Trip | +--------------------+------------+ Table 2 Gregorio & de hOra Expires April 14, 2006 [Page 24] Internet-Draft The Atom Publishing Protocol October 2005 10. Generic Collections Generic Collections are Collections that do not have uniform restrictions on the representations of the member resources. 10.1 Editing Generic Resources Member resources are edited by sending HTTP requests to an individual resource's URI. Servers can determine the processing necessary to interpret a request by examining the request's HTTP method and 'Content-Type' header. Processing| | | | atom:contributor | ClientRequests +----------+------+--------+--------+------+Writable | |GET|PUT|DELETE|POSTatom:id | Server Controlled | |+----------+------+--------+--------+------+|No Body|Read|xatom:link | Client Writable |Delete|x| | | atom:published | Client Writable | | | |Any Body|xatom:source | Client Writable | | | | | atom:summary | Client Writable | | | | | atom:title | Client Writable | | |Update|x|xatom:updated | Server Controlled | | | | | app:control |+----------+------+--------+--------+------+Client Writable | +--------------------+--------------------+ Table 1 8.3 Media Collections Media Collections are collections whose member representations are not constrained. They are identified by having an app:member-type of "media". 8.3.1 Editing Media Resources When aListmembership list resource returns an Atom Feed enumerating the contents of aGenericMedia Collection, all the Entries MUST have anatom:contentatom: content element with a 'src' attribute.10.2 Title: Header The POST to a Generic Collection Resource MAY containWhen creating aTitle: header that indicates the clients suggested title for the resource. The server MAY ignorepublic, read-only reference to theTitle: header or modifymember resource, a client SHOULD use therequested title to suit local conventions. Title = "Title" ":" [text]"atom:content/@src" attribute value. Gregorio & de hOra Expires April14,30, 2006 [Page25]20] Internet-Draft The Atom Publishing Protocol October 200511. List Resources List resources9. Listing Collections Collections, as identified in an Introspection Document, are resourceswhich are identified by URI templates indicating selection criteria. They can be used where clients require fine control overthat MUST provide representations in therange or sizeform ofa server's response. A list resource MUST return anAtomfeed document as its representation.Feed documents. The entries in the returneddocumentFeed MUST be ordered by their 'atom:updated' property, with the most recently updated entries coming first in the document order. Every entry in the Feed Document MUST have an atom:link element with a relation of "edit" (See Section 10.1). Clients MUST NOT assume thatthe entryan Atom Entry returned in thefeedFeed is a full representation of a member resource.IfThe value of atom:updated is only changed when theentrychange to a member resource isan Editable Resource thenconsidered significant. Insignificant changes do not result in changes to the atom:updated value and thus do not change the position of theclient shouldcorresponding entry in a membership list. Clients SHOULD be constructed with this in mind and SHOULD perform a GET on the member resource before editing.note:Collections can contain extremely large numbers of resources. A naive client such as a web spider or web browser would be overwhelmed if the response to a GET contained every entry inthis section some URIs carry across ontothenext line;feed, and the server would waste large amounts of bandwidth and processing time on clients unable to handle the response. For this reason, Introspection documents refer to collections not with IRIs but with IRI Templates, contained in the "app:member-type" child of "app:collection". An IRI Template isindicated by a '\' 11.1 URI Templates URI Templates areamechanism for declaring criteria againststring containing the embedded token "{index}". To produce an IRI that can be used to retrieve part or all of the collection, software replaces the "{index}" with alist resource. By itselfpair of positive integer indices separated by aURI Template is notdash character. An IRI template MUST, after such substitution has been performed, constitute a syntactically validURI. Instead there are multiple parameters embeddedIRI. One or other index MAY be omitted, in which case theURIrange is understood as stretching to 0 or infinity. The index values are 0 based anddistinguishedselect members from the collection based on the member's index, with all of the members ordered byclosing braces which can be populated and used astheir 'atom:updated' property. The response to the selection request MUST be an Atom Feed where all the entries fall within the requested criteria. Thevalue of each app:uri-template element in a Collection documentrequest range is considered aURI Template. Each URI template hasclosed set - if an entry matches oneor more parameters thatend of the range exactly it MUST besubstitutedincluded in the response. If no members fall in the requested range, the server MUST respond with an Atom Feed containing no entries. If a membership list is returned withvalues to constructavalid URI. The substitution MUST ensurenumber of entries thatthe resulting valueisalso properly percent-encoded utf-8. Here are some examplesless than the number oftemplate URIs and corresponding populated values: http://example.org/blog/edit/{index} http://example.org/blog/edit/3-9 http://example.org/blog/edit/{index}/foo http://example.org/blog/edit/0-100/foo http://example.org/blog/edit/{daterange} http://example.org/blog/edit/daterange=\ 2003-12-13T18:30:02Z-2003-12-13T18:30:02Z http://example.org/blog/edit?dr={daterange}/bar/ http://example.org/blog/edit?dr=\ 2003-12-13T18:30:02Z,2003-12-13T18:30:02Z/bar/ Note thatentries requested than theparametersclient MAYappear at any placeassume that it has made a request that exceeds the last index of the members. Gregorio & de hOra Expires April 30, 2006 [Page 21] Internet-Draft The Atom Publishing Protocol October 2005 For example, suppose the client is supplied this IRI template: http://example.org/blog/edit/{index} If the client wants the first 15 entries in theURI template.collection it would substitute the brace-delimited parameter {index}, with the value 0-14, giving: http://example.org/blog/edit/0-14 Gregorio & de hOra Expires April14,30, 2006 [Page26]22] Internet-Draft The Atom Publishing Protocol October 200511.2 URI Template Parameters10. Atom Entry Extensions This specificationdefines two parametersadds one new value to the Registry of Link Relations and also adds a new element to Atom Entries called "app: control" forusecontrolling publishing. These new links and app: control elements MAY appear inURI Templates: o index: allows selection into a collection's resources based as though ordered by their 'atom:updated' property. o daterange: allows selection into a collection's resources based on their 'atom:updated' property Inbothcases,membership lists and in member representations. 10.1 The 'edit' Link Relation This specification adds theresponsevalue "edit" to theselection request MUST be an Atom Feed where allRegistry of Link Relations. The value of "edit" signifies that theentries fall withinIRI in therequested criteria. The request rangevalue of the href attribute isconsideredthe IRI of the member resource, and is intended to be used to update and delete resources as described in this specification. 10.2 Publishing Control This specification also adds a new element to Atom Entries for controlling publishing. pubControl = element app:control { atomCommonAttributes, pubDraft? & extensionElement } pubDraft = element app:draft { "yes" | "no" } The "app:control" element MAY appear as aclosed set - if an entry matches one endchild of an "atom:entry" which is being created or updated via therange exactlyAtom Publishing Protocol. The "app:control" element, if itMUST be included in the response. If no members falldoes appear inthe requested range, the server MUST respond withanAtom Feed containing no entries. A Collection Documententry, MUSTcontainonly appear atleast two app:uri-template elements -most onefor the {index} parameter template and the other for the {daterange} parameter template.time. Thetwo parameters are not mutually exclusive"app:control" element and its children elements MAYappear togetherbe included ina single Template URI. 11.2.1 \{index\} URI template variableAtom Feed or Entry Documents. Thevalue"app:control" element is considered "foreign markup" as defined in Section 6 of the{index} criterion MUST be a pair of non-negative integer indices separated by a dash character. One or other indexAtom Syndication Format. The "app:control" element MAYomitted, in which case the range is understood as stretching to zero,contain exactly one app:draft element and MAY contain zero orinfinity. index-specifier = [index] "-" [index] For example, suppose the client is supplied this {index} URI template: http://example.org/blog/edit/{index} If the client wants the first 15 entriesmore extension elements as outlined in theCollection it would substitute the brace-delimited parameter {index}, with the value 1-15, giving: http://example.org/blog/edit/1-15 11.2.2 \{daterange\} URI template variable A URI Template with the variable 'daterange' allows querying forAtomEntriesSyndication Format, Section 6. Both clients and servers MUST ignore foreign markup present ina Collection according to their 'atom:updated' property.the app:control element that they do not know. Gregorio & de hOra Expires April14,30, 2006 [Page27]23] Internet-Draft The Atom Publishing Protocol October 2005 10.2.1 Thevalue of the {daterange} criterion should be a pair of ISO formatted dates separated by a dash character; either index may be optionally omitted, in which case the range is understood as stretching to infinity on that end. daterange-specifier = [iso-date] "," [iso-date]app:draft Element This specification defines only one child element for "app:control", "app:draft". The[iso-date] terminal MUST conform to the "date-time" productionnumber of "app:draft" elements in[RFC3339]. In addition, an uppercase "T" character"app:control" MUST beused to separate date and time, and an uppercase "Z" characterzero or one. Its content MUST bepresent inone of theabsencevalues "yes" or "no". A value ofa numeric time zone offset. For example, suppose"no" means that theclient is supplied this {daterange} URI Template: http://example.org/blog/edit/{daterange}entry MAY be made publicly visible. If theclient wants"app:draft" element is missing then theentries invalue is understood to be "no". That is, if "app:control" and/or thecollection between January"app:draft" elements are missing from an entry then the entry is considered not a draft andFebruary 2006 it would substitutecan be made publicly visible. Clients MUST understand "app:draft" elements and MUST NOT drop them from Atom Entries during editing. Clients MUST NOT operate on thebrace-delimited parameter {daterange} withexpectation that a server will honor thedesired selection value, giving this URI: http://example.org/blog/edit/2006-01-01T00:00:00Z,\ 2006-02-01T00:00:00Z 11.2.3 Other URI Template parameters Other specificationsvalue of an "app:draft" element. Servers MAYdefine new parameters for use in URI templatesignore "app:draft" elements anddeclared in the app:uri-template element.drop them from Atom Entries. Gregorio & de hOra Expires April14,30, 2006 [Page28]24] Internet-Draft The Atom Publishing Protocol October 200512. Atom Entry Extensions11. Example Thisspecification adds three new values to the Registryis an example ofLink Relations.a client creating a new entry with an image. Thevalue of 'collection' signifiesclient has an image to publish and an entry thatthe IRI in the value of the href is the Collectionincludes an HTML 'img' element that uses that image. In thisEntry belongs to. Any entry MAY contain a link withscenario we consider arelation of 'collection'. The value of 'edit' signifiesclient thatthe IRI in the valuehas IRIs ofthe href attribute identifies the resource that is used to edit the entry. That is, it is the URItwo collections, an entry collection and a media collection, both ofthe Entry aswhich were discovered through anEditable Resource.introspection document. ThevalueIRI of'srcedit' signifies thatthe entry collection is: http://example.net/blog/edit/ The IRIin the valueof thehref attribute identifies the resource that is used to editmedia collection is: http://example.net/binary/edit First the client creates a new image resourcepointed toby POSTing the'src' attribute of the atom:content element. That is, it isimage to the IRI of theatom:content@src as an Editable Resource. If a link element with a relation of "srcedit" is not given, then it's value defaults to the "src" attributemedia collection. POST /binary/edit/ HTTP/1.1 Host: example.net User-Agent: Thingio/1.0 Content-Type: image/png Content-Length: nnnn Title: A picture of thecontent element. List Resources for Generic Collections MUST return entries that have 'srcedit' links or MUST have a atom:content@src value. If the "srcedit" linkbeach ...binary data... The member resource ispresent,created andit's value isanempty string, then thereHTTP status code of 201 isno URI that can be treated inreturned. HTTP/1.1 201 Created Date: Fri, 25 Mar 2005 17:17:11 GMT Content-Length: nnnn Content-Type: application/atom+xml Location: http://example.net/binary/edit/b/129.png <?xml version="1.0" encoding="utf-8"?> <entry xmlns="http://www.w3.org/2005/Atom"> <title>A picture of theway such a value would be treated. Clients SHOULD usebeach.</title> <link rel="edit" href="http://example.net/binary/edit/b/129.png"/> <id>urn:uuid:1225c695-cfb8-4ebb-aaaa-568596895695</id> <updated>2005-09-02T10:30:00Z</updated> <summary>Waves</summary> <content type="image/png" src="http://example.net/binary/readonly/129.png"/> </entry> Gregorio & de hOra Expires April 30, 2006 [Page 25] Internet-Draft The Atom Publishing Protocol October 2005 The client then POSTs the"srcedit" valueAtom Entry that refers tomanipulate the resource withinthecontext ofnewly created image resource. Note that theAPP itself. Clients SHOULD preferclient takes the"atom:content@src" valueIRI http://example.net/binary/readonly/129.png and uses it inany other context. For example, iftheresource is an image, a client may replace'img' element in theimage data using a PUTEntry content: POST /blog/edit/ HTTP/1.1 Host: example.net User-Agent: Thingio/1.0 Content-Type: application/atom+xml Content-Length: nnnn <?xml version="1.0" encoding="utf-8"?> <entry xmlns="http://www.w3.org/2005/Atom"> <title>What I did on my summer vacation</title> <updated>2005-09-02T10:30:00Z</updated> <summary>Beach!</summary> <content type="xhtml" xml:lang="en"> <div xmlns="http://www.w3.org/1999/xhtml"> <p>We went to the"srcedit" value, and may even displaybeach for summer vacation. Here is apreviewpicture of theimage by fetching the "srcedit" URI. But when creating a public, read-only reference to the same image resource, the client should usewaves rolling in: <img src="http://example.net/binary/readonly/129.png" alt="A picture of the"atom:content@src" value.beach." /> </p> </div> </content> </entry> Gregorio & de hOra Expires April14,30, 2006 [Page29]26] Internet-Draft The Atom Publishing Protocol October 200513.12. Securing the Atom Protocol All instances of publishing Atom entries SHOULD be protected by authentication to prevent posting or editing by unknown sources. Atom servers and clients MUST support one of the following authentication mechanisms, and SHOULD support both. o HTTP Digest Authentication [RFC2617] o [@@TBD@@ CGI Authentication ref] Atom servers and clients MAY support encryption of theAtomsession using TLS[RFC2246].(see [RFC2246]). There are cases where an authentication mechanismmayis not be required, such as a publicly editable Wiki, or when usingthe PostURIPOST topostsend comments to a site that does not require authenticationto create comments. 13.1from a commenter. 12.1 [@@TBD@@ CGI Authentication] This authentication method is included as part of the protocol to allow Atom servers and clients that cannot use HTTP Digest Authentication but where the user can both insert its own HTTP headers and create a CGI program to authenticate entries to the server. This scenario is common in environments where the user cannot control what services the server employs, but the user can write their own HTTP services. Gregorio & de hOra Expires April14,30, 2006 [Page30]27] Internet-Draft The Atom Publishing Protocol October 200514.13. Security ConsiderationsBecause Atom is a publishing protocol, it is important that only authorized users can create and edit entries.The security of Atom is based on HTTP Digest Authentication and/or [@@TBD@@ CGI Authentication]. Any weaknesses in either of these authentication schemes will affect the security of the Atom Publishing Protocol. Both HTTP Digest Authentication and [@@TBD@@ CGI Authentication] are susceptible to dictionary-based attacks on the shared secret. If the shared secret is a password (instead of a random string with sufficient entropy), an attacker can determine the secret by exhaustively comparing the authenticating string with hashed results of the public string and dictionary entries. SeeRFC 2617[RFC2617] formore detailedthe description of the security properties of HTTP Digest Authentication. @@TBD@@ Talk here about using HTTP basic and digest authentication. @@TBD@@ Talk here about denial of service attacks using large XML files, or the billion laughs DTD attack. Gregorio & de hOra Expires April14,30, 2006 [Page31]28] Internet-Draft The Atom Publishing Protocol October 200515.14. IANA ConsiderationsAAn AtomCollectionIntrospection Document, when serialized as XML 1.0, can be identified with the following media type: MIME media type name: application MIME subtype name:atomcoll+xmlatomserv+xml Mandatory parameters: None. Optional parameters: "charset": This parameter has identical semantics to the charset parameter of the "application/xml" media type as specified in [RFC3023]. Encoding considerations: Identical to those of "application/xml" as described in [RFC3023], section 3.2. Security considerations: As defined in this specification.[[anchor31:[[anchor22: update upon publication]] In addition, as this media type uses the "+xml" convention, it shares the same security considerations as described in [RFC3023], section 10. Interoperability considerations: There are no known interoperability issues. Published specification: This specification.[[anchor32:[[anchor23: update upon publication]] Applications that use this media type: No known applications currently use this media type. Additional information: Magic number(s): As specified for "application/xml" in [RFC3023], section 3.2. File extension:.atomcoll.atomsrv Fragment identifiers: As specified for "application/xml" in [RFC3023], section 5. Gregorio & de hOra Expires April14, 2006 [Page 32] Internet-Draft The Atom Publishing Protocol October 2005 Base URI: As specified in [RFC3023], section 6. Macintosh File Type code: TEXT Person and email address to contact for further information: Joe Gregorio <joe@bitworking.org> Intended usage: COMMON Author/Change controller: IESG An Atom Introspection Document, when serialized as XML 1.0, can be identified with the following media type: MIME media type name: application MIME subtype name: atomserv+xml Mandatory parameters: None. Optional parameters: "charset": This parameter has identical semantics to the charset parameter of the "application/xml" media type as specified in [RFC3023]. Encoding considerations: Identical to those of "application/xml" as described in [RFC3023], section 3.2. Security considerations: As defined in this specification. [[anchor33: update upon publication]] In addition, as this media type uses the "+xml" convention, it shares the same security considerations as described in [RFC3023], section 10. Interoperability considerations: There are no known interoperability issues. Published specification: This specification. [[anchor34: update upon publication]] Applications that use this media type: No known applications currently use this media type. Additional information: Gregorio & de hOra Expires April 14,30, 2006 [Page33]29] Internet-Draft The Atom Publishing Protocol October 2005Magic number(s): As specified for "application/xml" in [RFC3023], section 3.2. File extension: .atomsrv Fragment identifiers: As specified for "application/xml" in [RFC3023], section 5.Base URI: As specified in [RFC3023], section 6. Macintosh File Type code: TEXT Person and email address to contact for further information: Joe Gregorio <joe@bitworking.org> Intended usage: COMMON Author/Change controller: This specification's author(s).[[anchor35:[[anchor24: update upon publication]] Gregorio & de hOra Expires April14,30, 2006 [Page34]30] Internet-Draft The Atom Publishing Protocol October 200516.15. References16.115.1 Normative References [AtomFormat] Nottingham, M. and R. Sayre, "The Atom Syndication Format", 1.0, July 2005. [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. [RFC2246] Dierks, T. and C. Allen, "The TLS Protocol Version 1.0", RFC 2246, January 1999. [RFC2616] Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P., and T. Berners-Lee, "Hypertext Transfer Protocol -- HTTP/1.1", RFC 2616, June 1999. [RFC2617] Franks, J., Hallam-Baker, P., Hostetler, J., Lawrence, S., Leach, P., Luotonen, A., and L. Stewart, "HTTP Authentication: Basic and Digest Access Authentication", RFC 2617, June 1999. [RFC3023] Murata, M., St. Laurent, S., and D. Kohn, "XML Media Types", RFC 3023, January 2001.[RFC3339] Klyne, G. and C. Newman, "Date and Time on the Internet: Timestamps", RFC 3339, July 2002.[RFC3986] Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, January 2005. [RFC3987] Duerst, M. and M. Suignard, "Internationalized Resource Identifiers (IRIs)", RFC 3987, January 2005. [W3C.REC-xml-20040204] Yergeau, F., Paoli, J., Sperberg-McQueen, C., Bray, T., and E. Maler, "Extensible Markup Language (XML) 1.0 (Third Edition)", W3C REC REC-xml-20040204, February 2004. [W3C.REC-xml-names-19990114] Hollander, D., Bray, T., and A. Layman, "Namespaces in XML", W3C REC REC-xml-names-19990114, January 1999. [W3C.REC-xmlbase-20010627] Marsh, J., "XML Base", W3C REC W3C.REC-xmlbase-20010627, June 2001. Gregorio & de hOra Expires April14,30, 2006 [Page35]31] Internet-Draft The Atom Publishing Protocol October 200516.215.2 Informative References [RNC] Clark, J., "RELAX NG Compact Syntax", December 2001. [W3C.REC-webarch-20041215] Walsh, N. and I. Jacobs, "Architecture of the World Wide Web, Volume One", W3C REC REC-webarch-20041215, December 2004. Gregorio & de hOra Expires April14,30, 2006 [Page 32] Internet-Draft The Atom Publishing Protocol October 2005 URIs [1] <http://www.imc.org/atom-protocol/index.html> Authors' Addresses Joe Gregorio (editor) BitWorking, Inc 1002 Heathwood Dairy Rd. Apex, NC 27502 US Phone: +1 919 272 3764 Email: joe@bitworking.com URI: http://bitworking.com/ Bill de hOra (editor) Propylon Ltd. 45 Blackbourne Square, Rathfarnham Gate Dublin, Dublin D14 IE Phone: +353-1-4927444 Email: bill.dehora@propylon.com URI: http://www.propylon.com/ Gregorio & de hOra Expires April 30, 2006 [Page 33] Internet-Draft The Atom Publishing Protocol October 2005 Appendix A. Contributors The content and concepts within are a product of the Atom community and the Atompub Working Group. Gregorio & de hOra Expires April 30, 2006 [Page 34] Internet-Draft The Atom Publishing Protocol October 2005 Appendix B. RELAX NG Compact Schema This appendix is informative. The Relax NG schema explicitly excludes elements in the APP namespace which are not defined in this revision of the specification. Requirements for APP Processors encountering such markup are given in Section 6.2 and Section 6.3 of [AtomFormat]. # -*- rnc -*- # RELAX NG Compact Syntax Grammar for the Atom Protocol namespace app = "http://purl.org/atom/app#" namespace local = "" start = appService # common:attrs appCommonAttributes = attribute xml:base { atomUri }?, attribute xml:lang { atomLanguageTag }?, undefinedAttribute* undefinedAttribute = attribute * - (xml:base | xml:lang | local:*) { text } atomUri = text atomLanguageTag = xsd:string { pattern = "[A-Za-z]{1,8}(-[A-Za-z0-9]{1,8})*" } # app:service appService = element app:service { appCommonAttributes, ( appWorkspace+ & extensionElement* ) } # app:workspace appWorkspace = element app:workspace { appCommonAttributes, attribute title { text }, Gregorio & de hOra Expires April 30, 2006 [Page 35] Internet-Draft The Atom Publishing Protocol October 2005 ( appCollection+ & extensionElement* ) } # app:collection appCollection = element app:collection { appCommonAttributes, attribute title { text }, attribute href { text }, ( appMemberType & appListTemplate & extensionElement* ) } # app:member appMemberType = element app:member-type { appCommonAttributes, ( appTypeValue ) } appTypeValue = "entry" | "media" # app:list-template appListTemplate = element app:list-template { appCommonAttributes, ( appUriTemplate ) } # Whatever an IRI template is, it contains at least {index} appUriTemplate = xsd:string { pattern = ".+\{index\}.*" } # Simple Extension simpleExtensionElement = element * - app:* { text } # Structured Extension Gregorio & de hOra Expires April 30, 2006 [Page 36] Internet-Draft The Atom Publishing Protocol October 2005URIs [1] <http://www.imc.org/atom-protocol/index.html> Authors' Addresses Joe Gregorio (editor) BitWorking, Inc 1002 Heathwood Dairy Rd. Apex, NC 27502 US Phone: +1 919 272 3764 Email: joe@bitworking.com URI: http://bitworking.com/ Bill de hOra (editor) Propylon Ltd. 45 Blackbourne Square, Rathfarnham Gate Dublin, Dublin D14 IE Phone: +353-1-4927444 Email: bill.dehora@propylon.com URI: http://www.propylon.com/structuredExtensionElement = element * - app:* { (attribute * { text }+, (text|anyElement)*) | (attribute * { text }*, (text?, anyElement+, (text|anyElement)*)) } # Other Extensibility extensionElement = simpleExtensionElement | structuredExtensionElement # Extensions anyElement = element * { (attribute * { text } | text | anyElement)* } # EOF Gregorio & de hOra Expires April14,30, 2006 [Page 37] Internet-Draft The Atom Publishing Protocol October 2005 AppendixA. Contributors The contentC. Revision History draft-ietf-atompub-protocol-06 - Removed: Robert Sayre from the contributors section per his request. Added in PaceCollectionControl. Fixed all the {daterange} verbage andconcepts within areexamples so they all use aproductdash. Added full rnc schema. Collapsed Introspection and Collection documents into a single document. Removed {dateRange} queries. Renamed search to list. Moved discussion of media and entry collection until later in theAtom communitydocument and tied theAtompub Working Group. Robert Sayre was an editor for drafts 00-04. Gregorio & de hOra Expires April 14, 2006 [Page 38] Internet-Draft The Atom Publishing Protocol October 2005 Appendix B. Revision Historydiscussion to the Introspection element app:member-type. draft-ietf-atompub-protocol-05 - Added: Contributors section. Added: de hOra to editors. Fixed: typos. Added diagrams and description to model section. Incorporates PaceAppDocuments, PaceAppDocuments2, PaceSimplifyCollections2 (large-sized chunks of it anyhow: the notions of Entry and Generic resources, the section 4 language on the Protocol Model, 4.1 through 4.5.2, the notion of a Collection document, as in Section 5 through 5.3, Section 7 "Collection resources", Selection resources (modified from pace which talked about search); results in major mods to Collection Documents, Section 9.2 "Title: Header" and brokeout para to section 9.1 Editing Generic Resources). Added XML namespace and language section. Some cleanup of front matter. Added Language Sensitivity to some attributes. Removed resource descriptions from terminology. Some juggling of sections. See: http://www.imc.org/atom-protocol/mail-archive/msg01812.html. draft-ietf-atompub-protocol-04 - Add ladder diagrams, reorganize, add SOAP interactions draft-ietf-atompub-protocol-03 - Incorporates PaceSliceAndDice3 and PaceIntrospection. draft-ietf-atompub-protocol-02 - Incorporates Pace409Response, PacePostLocationMust, and PaceSimpleResourcePosting. draft-ietf-atompub-protocol-01 - Added in sections on Responses for the EditURI. Allow 2xx for response to EditURI PUTs. Elided all mentions of WSSE. Started adding in some normative references. Added the section "Securing the Atom Protocol". Clarified that it is possible that the PostURI and FeedURI could be the same URI. Cleaned up descriptions for Response codes 400 and 500. Rev draft-ietf-atompub-protocol-00 - 5Jul2004 - Renamed the file and re-titled the document to conform to IETF submission guidelines. Changed MIME type to match the one selected for the Atom format. Numerous typographical fixes. We used to have two 'Introduction' sections. One of them was moved into the Abstract the other absorbed Gregorio & de hOra Expires April 30, 2006 [Page 38] Internet-Draft The Atom Publishing Protocol October 2005 the Scope section. IPR and copyright notifications were added. Rev 09 - 10Dec2003 - Added the section on SOAP enabled clients and servers. Rev 08 - 01Dec2003 - Refactored the specification, merging the Introspection file into the feed format. Also dropped the distinction between the type of URI used to create new entries and the kind used to create comments. Dropped user preferences.Gregorio & de hOra Expires April 14, 2006 [Page 39] Internet-Draft The Atom Publishing Protocol October 2005Rev 07 - 06Aug2003 - Removed the use of the RSD file for auto- discovery. Changed copyright until a final standards body is chosen. Changed query parameters for the search facet to all begin with atom- to avoid name collisions. Updated all the Entries to follow the 0.2 version. Changed the format of the search results and template file to a pure element based syntax. Rev 06 - 24Jul2003 - Moved to PUT for updating Entries. Changed all the mime-types to application/x.atom+xml. Added template editing. Changed 'edit-entry' to 'create-entry' in the Introspection file to more accurately reflectit'sits purpose. Rev 05 - 17Jul2003 - Renamed everything Echo into Atom. Added version numbers in the Revision history. Changed all the mime-types to application/atom+xml. Rev 04 - 15Jul2003 - Updated the RSD version used from 0.7 to 1.0. Change the method of deleting an Entry from POSTing <delete/> to using the HTTP DELETE verb. Also changed the query interface to GET instead of POST. Moved Introspection Discovery to be up under Introspection. Introduced the term 'facet' for the services listed in the Introspection file. Rev 03 - 10Jul2003 - Added a link to the Wiki near the front of the document. Added a section on finding an Entry. Retrieving an Entry now broken out intoit'sits own section. Changed the HTTP status code for a successful editing of an Entry to 205. Rev 02 - 7Jul2003 - Entries are no longer returned from POSTs, instead they are retrieved via GET. Cleaned up figure titles, as they are rendered poorly in HTML. All content-types have been changed to application/atom+xml. Rev 01 - 5Jul2003 - Renamed from EchoAPI.html to follow the more commonly used format: draft-gregorio-NN.html. Renamed all references to URL to URI. Broke out introspection intoit'sits own section. Added the Revision History section. Added more to the warning that the example URIs are not normative. Gregorio & de hOra Expires April14,30, 2006 [Page40]39] Internet-Draft The Atom Publishing Protocol October 2005 Intellectual Property Statement The IETF takes no position regarding the validity or scope of any Intellectual Property Rights or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; nor does it represent that it has made any independent effort to identify any such rights. Information on the procedures with respect to rights in RFC documents can be found in BCP 78 and BCP 79. Copies of IPR disclosures made to the IETF Secretariat and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementers or users of this specification can be obtained from the IETF on-line IPR repository at http://www.ietf.org/ipr. The IETF invites any interested party to bring to its attention any copyrights, patents or patent applications, or other proprietary rights that may cover technology that may be required to implement this standard. Please address the information to the IETF at ietf-ipr@ietf.org. The IETF has been notified of intellectual property rights claimed in regard to some or all of the specification contained in this document. For more information consult the online list of claimed rights. Disclaimer of Validity This document and the information contained herein are provided on an "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Copyright Statement Copyright (C) The Internet Society (2005). This document is subject to the rights, licenses and restrictions contained in BCP 78, and except as set forth therein, the authors retain all their rights. Gregorio & de hOra Expires April14,30, 2006 [Page41]40] Internet-Draft The Atom Publishing Protocol October 2005 Acknowledgment Funding for the RFC Editor function is currently provided by the Internet Society. Gregorio & de hOra Expires April14,30, 2006 [Page42]41] ----