Signed-Headers or Signed-Fields
Open
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 1.3k
- Forks
- 125
- PR merge metrics
- No merged PRs in 30d
Description
Question
Signed-Headers is defined as a response header field. I was guessing whether:
- constraining its usage to Headers might hinder the ability to evolve this specification in conjunction with other content-coding != mice. Ongoing
Digestwork for example allows usingDigestin trailers, while there's an open discussion in http on mid-stream trailers; - constraining its usage to responses could inhibit the integration between this specification and other signature-based specifications, eg. https://github.com/httpwg/http-extensions/issues/1181
A more general approach (eg. Signed-Fields) could make sense.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the Signed-Headers definition in the relevant Web Packaging specification, then compare the questions about request versus response use and headers versus trailers. Read the linked Digest trailers change, mid-stream trailers discussion, and issue 1181. Done means the scope is resolved and the specification has an agreed terminology and behavior.
Written by the indexing model from the issue text.
Assessment
- Domain
- api
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100