Require support for both mdoc and signed OpenID4VP protocols - #454
Require support for both mdoc and signed OpenID4VP protocols#454marcoscaceres wants to merge 27 commits into
Conversation
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
|
Added test web-platform-tests/wpt#57557 |
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
|
Would it potentially help resolve another objection (@bc-pi) if we made ISO-18103-7 optional rather than recommended, and explained in a note that we have concerns about process and access but feel it's necessary to include because of implementer demand or issuer usage? |
|
Discussed on 27 July 2026. Reminder that there is another PR related to this topic: #474 |
RByers
left a comment
There was a problem hiding this comment.
FWIW making OpenID4VP mandatory SGTM - it's a clear interoperability improvement IMHO.
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Thanks @npdoty and sorry I didn't see this until just now. That would be a good direction, I think, but I don't see how issuer usage actually has anything to do with it and would want to accurately represent what is meant by implementer demand. |
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
|
OID4VP 1.0 is one protocol, with 3 operating modes. Requiring support for the protocol must include the entire protocol. This PR currently leaves out one of the modes (unsigned). |
There was a problem hiding this comment.
That was my question as well during the Series A call today, why do we have a carve-out for user agents to only support the signed variants of OID4VP when unsigned OID4VP is also in the "Table of supported presentation and issuance protocols"?
If someone in the WG doesn't want user agents to support unsigned protocols then they should make the case to the WG. If consensus can be reached then we remove unsigned OID4VP from the table and that's how we get agents to "only support signed protocols." Otherwise DC API should require user agents to support the protocols that are listed in the table of supported protocols so that verifiers can have a single place to look to see what protocols DC API supports. Not "what protocols the DC API call recognizes, except for this other section that says that browsers can choose to ignore some of the entries."
|
Continued discussion on 10 August 2026 call. |
|
@MasterKale seems you missed #568 -Someone 🤭 |
|
Closes #439
Closes #474
The following tasks have been completed:
Implementation commitment:
Documentation and checks
Preview | Diff