On 7/20/21 12:14 PM, Adrian Gropper wrote:
> The linkage of control to possession based on OAuth 2-style API client 
> credentials gives the sovereign Issuer the ability to censor or specify
> the end-user's client.

Replace "Oauth2" with /any authorization mechanism/ and you still have the
same problem.

The server can always deny requests, even legitimate ones. Full. Stop.

An Internet-based server can always censor an Internet-based client. If this
were not possible, every server on the Internet could be Denial-of-Service'd
out of existence.

I continue to be convinced that you don't understand what the Issuer endpoints
of the VC HTTP API do:


Either that, or I'm being fantastically dense (which I do admit is a
possibility). Please help me understand... how is what I said above not true?

-- manu

