w3c/websec

secure transaction confirmation (by rigo)

Opened this issue · 1 comments

It would be great to adresss "scoped bearer tokens" in the sceure transaction confirmation. Like, to add the origin context into the transaction to avoid replay attacks. The current text rather looks to me like unscoped bearer tokens.

@rigow Rigo: but the API already includes the origin which is the URL of the requesting website. What do you want to add here ?