Jetty 12 - Investigate how to handle HTTP Message Signatures
Open
Enhancement
Help Wanted
Specification
- Dominant language
- Java
- Stars
- 4.1k
- Forks
- 2k
- Avg merge
- 3d 56m
- Merged PRs (30d)
- 48
Description
**Jetty version(s)**
Jetty 12
**Description**
HTTP Request/Message Signatures is becoming popular in some contexts. (eg: OAuth)
We should either support it, or at least document how to support it.
* https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12
* https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-message-signatures
Contributor guide
Research direction
Start by reading the two linked HTTP Message Signatures drafts and compare their requirements with Jetty 12's request handling. Decide whether the outcome should be implementation support or documentation, then define the affected entry points and tests; the issue names no files or existing tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- api, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100