indieweb / indieweb/indieauth

Discourage use of insecure HTTP for client_id and redirect_uri?

Open
#119 3 comments 1 reaction 0 assignees View on GitHub
Dominant language
HTML
Stars
57
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Per https://indieauth.spec.indieweb.org/#client-identifier:

>Client identifier URLs MUST have either an https or http scheme

But the spec does not discourage the latter, nor whether the server may reject the latter, and same for `redirect_uri`. Should there be some explicit discouragement?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the client identifier section at https://indieauth.spec.indieweb.org/#client-identifier and review the issue comments for any existing decision. Done means reaching a clear decision on HTTP client_id and redirect_uri handling and updating the relevant specification text accordingly.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.