dfinity / wg-identity-authentication

Repository of the Identity and Wallet Standards Working Group
https://wiki.internetcomputer.org/wiki/Identity_%26_Authentication
Apache License 2.0
27 stars 8 forks source link

ICRC-21: Specify that the consent message request requires authentication #53

Closed frederikrothenberger closed 9 months ago

frederikrothenberger commented 9 months ago

This PR extends ICRC-21 with additional details regarding the icrc21_consent_message canister call. It specifies the authentication requirement and warns developers to not implement the standard that would create "time of check, time of use" vulnerabilities.