w3c / vc-data-model

W3C Verifiable Credentials v2.0 Specification
https://w3c.github.io/vc-data-model/
Other
299 stars 106 forks source link

Require digest verification for related resources. #1567

Closed msporny closed 1 month ago

msporny commented 1 month ago

This PR is an attempt to address https://github.com/w3c/vc-data-integrity/issues/272 by requiring digest verification for related resources.


Preview | Diff

iherman commented 1 month ago

@msporny I believe there is a github manipulation error. The 'diff' file shows over 1000 changes, mostly editorials, which makes it difficult to review. I presume the subject of this PR is only §5.3 on the Integrity of Related Resources...

msporny commented 1 month ago

@msporny I believe there is a github manipulation error. The 'diff' file shows over 1000 changes, mostly editorials, which makes it difficult to review. I presume the subject of this PR is only §5.3 on the Integrity of Related Resources...

This is what I see when I view the diff on Github:

image

There was an issue initially, which created the issue you mention, but I fixed that last night. I expect you probably hit a cache somewhere that gave you the old version. Try a hard refresh?

iherman commented 1 month ago

It may be there is a cache issue, but not mine... I have made a clean reload, and I have also looked at the diff file from browsers that I have never used for this purpose. I still see changes in the abstract or the introduction, for example:

Screenshot 2024-10-01 at 16 47 17

Anyway. I can concentrate on the part that you highlight, maybe this exchange is good enough for other reviewers to disregard the rest...

iherman commented 1 month ago

B.t.w., if I look at the "Files changed" tab, then I get what you really changed only. Something with the preview cache...

iherman commented 1 month ago

The issue was discussed in a meeting on 2024-10-09

View the transcript #### 2.1. Require digest verification for related resources. (pr vc-data-model#1567) _See github pull request [vc-data-model#1567](https://github.com/w3c/vc-data-model/pull/1567)._ **Manu Sporny:** I took an action to raise a PR in VCDM 2.0 for requiring digest verification if it's provided, there has been some discussion on it, I wanted the group to see that this is out there, there are some suggested changes, I will process this and merge it by the end of the week, please get in there and provide commentary, hopefully the PR reflects consensus in the group. I plan to close the DI issue based on the merge of requiring digest verification if it's provideds provided.
msporny commented 1 month ago

Normative, multiple reviews, changes requested and made, no objections, merging.