jetty / jetty/jetty.project

Jetty 12 - Investigate how to handle HTTP Message Signatures

Open
#9,209 1 comment 0 reactions 0 assignees View on GitHub
Enhancement Help Wanted Specification
Dominant language
Java
Stars
4.1k
Forks
2k
Avg merge
3d 56m
Merged PRs (30d)
48

Description

**Jetty version(s)**
Jetty 12

**Description**
HTTP Request/Message Signatures is becoming popular in some contexts. (eg: OAuth)
We should either support it, or at least document how to support it.

* https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12
* https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-message-signatures

Contributor guide

Open the contributing guide

Research direction

Start by reading the two linked HTTP Message Signatures drafts and compare their requirements with Jetty 12's request handling. Decide whether the outcome should be implementation support or documentation, then define the affected entry points and tests; the issue names no files or existing tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.