Re: [w3ctag/design-reviews] Private State Tokens (formerly Trust Tokens) (Issue #780)

The main changes are:
- Addition of a Sec-Trust-Token-Lifetime header to limit the lifetime of redemption records (based on OT feedback).
- Removal of the signed outgoing request extension as it was complicated and unused during testing.
- Addition of a spec document (https://github.com/WICG/trust-token-api/blob/main/spec.bs, https://wicg.github.io/trust-token-api/index.html)
- Rename to Private State Tokens (and generalizing the API surface to support other types of Private tokens).

In the IETF, the privacypass protocol is reaching WGLC (to be turned into an IETF RFC) and should hopefully be done in the next month or so, we'll rebase parts of the PST specification on top of that, though there are a few features/extensions to that protocol that we'd like to have on top of/replace so will likely have some delta with that spec.

There's been some support during the OT from other companies and interest by Edge (https://github.com/MicrosoftEdge/MSEdgeExplainers/blob/main/TrustTokenExtensions/IssuerRedemptionStatistics.md) though we haven't gotten strong signals on other browser engine support for the API.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/780#issuecomment-1346338444
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/780/1346338444@github.com>

Received on Monday, 12 December 2022 11:49:20 UTC