Re: [w3ctag/design-reviews] Private State Tokens (formerly Trust Tokens) (Issue #780)

The original reason was that since you could have multiple redemption records that you might want to send depending on the context, having the top-level site explicitly indicate which records to attach allowed for more explicit control of what was being attached to each request from the site.

Some extensions we've thought about is the top level site being able to indicate that all requests to specific origins should include RRs from a particular issuer (or the Optimizing redemption RTT where origins request specific tokens via HEAD headers), but at least during the initial experiments it wasn't a hard requirement for the API so we wanted to land the more explicit API before adding extensions to optimize the inclusion of redemption records.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/780#issuecomment-1353464393
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/780/1353464393@github.com>

Received on Thursday, 15 December 2022 17:36:27 UTC