You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think we discussed this in the past, but couldn't find an open issue for it. If it does exist (i.e. this is a duplicate), this issue can be closed.
DCQL says that if the claims parameter is absent: 'If claims is absent, the Verifier requests all claims existing in the Credential.' The existence of this option has a number of privacy problems and UI/UX issues which include:
It makes the easiest request option from an RP perspective (just request everything) the least privacy preserving option.
It allows an RP to make a request for sensitive claims seem less intrusive by not explicitly requesting the sensitive claims.
Given these privacy issues, we should either remove the option for 'claims' being absent, or define that when that's the case no claims are requested.
The text was updated successfully, but these errors were encountered:
I think we discussed this in the past, but couldn't find an open issue for it. If it does exist (i.e. this is a duplicate), this issue can be closed.
DCQL says that if the claims parameter is absent: 'If claims is absent, the Verifier requests all claims existing in the Credential.' The existence of this option has a number of privacy problems and UI/UX issues which include:
Given these privacy issues, we should either remove the option for 'claims' being absent, or define that when that's the case no claims are requested.
The text was updated successfully, but these errors were encountered: