w3c-ccg / zcap-spec

WORK ITEM: Authorization Capabilities (ZCAP) specification
https://w3c-ccg.github.io/zcap-spec/
Other
30 stars 10 forks source link

Integrity validation of keys and capability documents should be a MUST #21

Open cwebber opened 5 years ago

cwebber commented 5 years ago

It MUST not be possible to swap out keys or capability documents unexpectedly. In general, I think this makes the case for immutability such as content addressing of capability documents and keys, but I think there's a case that could be made that a blockchain's level of integrity may still be okay (I am not convinced).

Note this only applies when linking; when embedding there are no problems.