Skip to content

user agents should limit to protocols listed in the registry that meet the group's requirements #288

@npdoty

Description

@npdoty

The spec includes a registry for exchange protocols (and document formats) and has some normative requirements and some non-normative considerations regarding inclusion in that protocol.

However, it's possible (in fact, almost certain, given current implementers' stated plans) that protocols that don't meet those requirements will still be accepted by browsers and passed on to wallets.

The spec should add a requirement that browsers only support requests with protocols listed in the registry (and that meet the requirements for inclusion in the registry). Or, if there is some good reason for more flexibility, there could be a should requirement, with stated acceptable reasons for those kind of exceptions.

Without such a requirement, the effort to manage a registry of protocols and doing privacy and security reviews would not have any actual effect.

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions