openid / openid/OpenID4VP

(Question) How does a wallet find response_uri and its legitimacy?

Open
#508 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
Shell
Stars
112
Forks
38
Avg merge
12d 19h
Merged PRs (30d)
4

Description

Sorry, if it was answered before but my search did not give an answer.
This question came up while writing the privacy considerations.

  • How does a wallet find response_uri and its legitimacy?

Figure 3 seems to indicate that it is sent as a part of the Authorization Request. However, it does not appear in 5.1. New Parameters

Client metadata in RFC7591 of course does not have it.
11.1. Additional Verifier Metadata Parameters only specifies vp_formats.

Let me know.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read Figure 3, section 5.1, and section 11.1 of the linked OpenID4VP draft, then compare how response_uri is described with RFC7591 client metadata. Done means resolving how a wallet discovers response_uri and establishes its legitimacy, with the answer reflected in the privacy considerations.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.