openid / openid/OpenID4VCI

Wallet Consent

Open
#85 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
125
Forks
41
PR merge metrics
No merged PRs in 30d

Description

Should the specification be more explicit about what consent the wallet should collect from the user. During the working group meeting prior to IIW, two wallet consents were discussed.

  1. Does the user trust the issuer (of the credentials)
  2. Does the user consent to storing the retrieved credentials from the issuance endpoint?

It may be possible to skip the first consent if the wallet and issuer are "first party" to each other.

Are there attacks that can be accomplished against the user if these consents are skipped?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the specification's treatment of wallet consent and the two consent cases described in this issue. Determine whether skipping either consent enables attacks, and document a settled requirement for issuer trust and credential storage consent; completion requires agreement on the specification change.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.