Skip to content

Submit PAP specification for formal adversarial review and IETF RFC track #210

@toadkicker

Description

@toadkicker

docs/blog-post.md lists formal RFC submission as an explicit near-term goal: "What it does not yet have: … a formal RFC submission. Those come next." The spec is v1.0 and stable enough for external review, but hasn't been submitted anywhere for structured feedback.

Work required:

  • Clean up docs/specification.md to strict RFC 2119 MUST/SHOULD/MAY language throughout
  • Add IANA considerations section (new URI scheme pap://, media type application/pap+json)
  • Add security considerations section (replay attacks, scope escalation, key compromise)
  • Submit as an IETF Internet-Draft to the oauth or dispatch working group, or to the W3C Credentials CG
  • Alternatively: open a public comment period as a GitHub Discussions thread first
  • Tag the review request with a deadline (e.g., 60 days)

References: docs/specification.md, docs/blog-post.md, SECURITY.md

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions