Discourage use of insecure HTTP for client_id and redirect_uri?
Open
- Dominant language
- HTML
- Stars
- 57
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Per https://indieauth.spec.indieweb.org/#client-identifier:
>Client identifier URLs MUST have either an https or http scheme
But the spec does not discourage the latter, nor whether the server may reject the latter, and same for `redirect_uri`. Should there be some explicit discouragement?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the client identifier section at https://indieauth.spec.indieweb.org/#client-identifier and review the issue comments for any existing decision. Done means reaching a clear decision on HTTP client_id and redirect_uri handling and updating the relevant specification text accordingly.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100