<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#467886;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:11.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">While working on <a href="https://github.com/openid/OpenID4VP/issues/227">
https://github.com/openid/OpenID4VP/issues/227</a>, I encountered a kind of message defined by OpenID4VP for which there isn’t a name. Other message types, such as Authorization Request, Token Response, Presentation Request, etc. have names in the spec, which
is useful to the reader.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a href="https://openid.net/specs/openid-4-verifiable-presentations-1_0-21.html#name-response-mode-direct_post">https://openid.net/specs/openid-4-verifiable-presentations-1_0-21.html#name-response-mode-direct_post</a> contains this text
describing an instance of a parameter for this unnamed message type:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The following new parameter is defined for use in the response from the endpoint:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">redirect_uri:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">OPTIONAL. String containing a URI. When this parameter is present the Wallet MUST redirect the User Agent to this URI. This allows the Verifier to continue the interaction with the End-User on the device where
the Wallet resides after the Wallet has sent the Authorization Response to the Response Endpoint. It can be used by the Verifier to prevent session fixation (<a href="https://openid.net/specs/openid-4-verifiable-presentations-1_0-21.html#session_fixation">Section
12.2</a>) attacks. The Response Endpoint MAY return the redirect_uri parameter in response to successful Authorization Responses or for Error Responses.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">First, to possibly help us think about what this kind of parameter should be called, would it be a correct clarification to change:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The following new parameter is defined for use in the
<span style="background:yellow;mso-highlight:yellow">response from the endpoint</span>:<o:p></o:p></p>
<p class="MsoNormal">to:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The following new parameter is defined for use in the
<span style="background:yellow;mso-highlight:yellow">response from the Response Endpoint to the Wallet</span>:<o:p></o:p></p>
<p class="MsoNormal">?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">If I’m right about the above, then currently we’d be calling the response something like “the response from the Response Endpoint to the Wallet” and the parameters for it “parameters used in the response from the Response Endpoint to the
Wallet”. But hopefully we can name these things to make the exposition cleaner.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any suggested names? Will you be the lucky winner?!!! ;-)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> Thanks,<o:p></o:p></p>
<p class="MsoNormal"> -- Mike<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">P.S. Of course, if I failed to notice a name that’s already right under my nose, feel free to point out what I missed. :-)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>