w3c / did-resolution

RELEASED DRAFT: Decentralized Identifier Resolution (DID Resolution) 0.2 Specification
https://w3c.github.io/did-resolution/
Other
14 stars 9 forks source link

Disallow JSON-LD remote context retrieval #53

Open peacekeeper opened 4 years ago

peacekeeper commented 4 years ago

@awoie made a good suggestion that JSON-LD context files must not be retrieved from a remote location in a production environment. The DID Resolution spec could state this explicitly. See https://lists.w3.org/Archives/Public/public-credentials/2020Jan/0066.html

awoie commented 4 years ago

A lot of people will probably only implement normative statements from the spec. After the conversation on the mailing list, I have the perception that nobody uses remote retrieval in practice and it is considered to be bad practice. So, we should make this a normative statement.