-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Description
All resources used in the context of Solid Authentication and Authorization MUST use a secure protocol.
Namely, a WebID used for Authentication MUST use the https protocol. That is true of both client and user WebIDs.
Currently, the specification states: "a WebID is a HTTP URI". I couldn't find any specific requirements about security in transit.
I appreciate that it seems a bit like stating the obvious, but I reckon it is fundamentally important enough to require an extension of section 3, probably with a 3.2 Encryption of WebIDs in transit.
Metadata
Metadata
Assignees
Labels
No labels