web-payments / web-payments.org

Web Payments website and core specifications
https://web-payments.org/
29 stars 13 forks source link

Requestor of identity information should be displayed when writing to identity #14

Open msporny opened 10 years ago

msporny commented 10 years ago

There's no information about what the identity provider can display to the identity owner to indicate who they are providing access to their information to via the POST callback method.

There needs to be some description of what information the IDP can use to display to the IDO. The HTTP signature part should probably also touch on this by indicating that the key needs to be tied to an identity that can be read with information that can be displayed to the IDO in other words, this protocol needs to specify how information can be shown to the IDO so they can make an informed decision about whether or not they should let their info be given out.