- From: Heather Flanagan <notifications@github.com>
- Date: Mon, 03 Aug 2026 09:49:39 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Monday, 3 August 2026 16:49:43 UTC
hlflanagan left a comment (w3ctag/design-reviews#1157) Hi, sorry for the delay on this one. I don't see any blockers for this going ahead to CR. While you continue the work, however, I have two points for you to consider: One thing I noticed outside dereferencing: the resolver architecture describes bindings as independent ways of exposing the abstract resolution function, including local libraries, command-line tools, and HTTP APIs. It also defines a network-based resolver as a resolver that additionally implements the HTTP(S) binding. But the HTTP binding then says that “all conforming DID resolvers MUST implement the GET version” of that binding. Is that intended? As written, it seems to require even local/library implementations to expose an HTTP endpoint, which doesn't seem consistent with the architecture described earlier. In the security section, is the statement that DID resolution does not involve authentication or authorization intended to describe the abstract resolution operation rather than resolver deployments or bindings? The current wording seems broader than the HTTP binding, which explicitly contemplates authenticated requests. -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/1157#issuecomment-5169246255 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/1157/5169246255@github.com>
Received on Monday, 3 August 2026 16:49:43 UTC