w3c-fedid / FedCM

A privacy preserving identity exchange Web API
https://w3c-fedid.github.io/FedCM/
Other
383 stars 73 forks source link

Account picture formats #600

Open obfuscoder opened 6 months ago

obfuscoder commented 6 months ago

The FedCM spec does not seem to mention what formats/mediatypes are accepted for the account picture. I think IdPs as well as browser vendors would need to know what they can use or need to support. For instance, would the content type image/svg+xml be an acceptable image format?

npm1 commented 6 months ago

Yea, it would be valuable to make this more explicit. For what it's worth I don't see any content type checks in our code for this image fetch so I imagine that one would be accepted.