@hrefna
The biggest value of http signatures is that they're not forwardable. They also provide some forgery protection. And as long as we're relying on self-asserted credentials, it's no worse of an authn mechanism than anything else. But you're right they convey no authorization, and that's something I wish we had.
Jenniferplusplus (jenniferplusplus@hachyderm.io)'s status on Friday, 15-Nov-2024 04:01:44 JST
-
Embed this notice
Jenniferplusplus (jenniferplusplus@hachyderm.io)'s status on Friday, 15-Nov-2024 04:01:44 JST Jenniferplusplus