[Openid-specs-ab] Issue #1210: SIOP V2: openid:// should not be required but an optional URI scheme (openid/connect)
Adam Lemmon
issues-reply at bitbucket.org
Sun Feb 21 20:10:28 UTC 2021
New issue 1210: SIOP V2: openid:// should not be required but an optional URI scheme
https://bitbucket.org/openid/connect/issues/1210/siop-v2-openid-should-not-be-required-but
Adam Lemmon:
Hi All
**Preface:** A solution to wallet discovery is out of scope for this issue :slight_smile:
It appears the same conclusion presented below was also reached here [#1199](https://bitbucket.org/openid/connect/issues/1199/which-wallet-gets-invoked-in-siop) and some recent commentary here too [#1207](https://bitbucket.org/openid/connect/issues/1207/custom-url-scheme-clarification-needed).
But as per last week’s SIOP V2 review it appeared that `openid://` was still marked as **required.** Perhaps this is just a matter of the update still needing to be made to the document but we wanted to make sure this one was flagged for revision.
Currently section 2.1 of [Self-Issued OpenID Provider V2, draft 01](https://bitbucket.org/openid/connect/src/master/openid-connect-self-issued-v2-1_0.md) states:
* _**Self-Issued OP MUST associate a custom schema**_ `openid://` _**with itself. Relying Party MUST call**_ `openid://` _**when sending a request to a Self-Issued OP.**_
Without diving into alternative solutions for discovery \(being discussed elsewhere\), for the scope of this issue we hope to simply reach consensus with the following statement:
* **openid:// should not be required but noted as an optional URI scheme.**
We present this as `openid://` does not sufficiently account for the following scenarios:
1. Support for various deployment architectures such as PWAs or cloud servers, likely addressable behind https://
2. The holder has multiple wallets on a single device
3. The holder has multiple wallets across multiple devices
If others are also of this opinion than we’d be happy to collaborate on alternative language for this section.
Thanks!
More information about the Openid-specs-ab
mailing list