-
Notifications
You must be signed in to change notification settings - Fork 29
Description
User agents can help users make decisions about credential presentation, and filter out inappropriate or invasive uses of the credential API, if there is some documented commitment regarding a limited set of purposes for which the site will request credentials.
Sites could indicate (at a well-known location, and perhaps with the signature of a registrar or auditor) what information they will request and what purpose it would be used for. User agents can consume that information in real-time, and researchers/policymakers can review it to detect malfeasance and provide accountability.
(This is related to #136 before that was re-titled to focus on the protocol registry only. #209 also proposes to reflect some of that information for the user in the prompt itself.)