From 930b5174357449aeece3139eb80012c7dc5f87a0 Mon Sep 17 00:00:00 2001 From: phil Date: Wed, 2 Jul 2025 17:14:00 -0400 Subject: [PATCH] note the lack of jwt --- who-am-i/readme.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/who-am-i/readme.md b/who-am-i/readme.md index 3df653e..66247d3 100644 --- a/who-am-i/readme.md +++ b/who-am-i/readme.md @@ -44,3 +44,8 @@ since the requirements (read-only, just verifying identity) seem modest, i was h it's still nice to have an explicit opt-in on a per-demo basis for microcosm so it will be used for that. it's allow-listed for the microcosm domain however (so not deployed on any adversarial hosting pages), so it's simultaenously overkill and restrictive. i will get back to oauth eventually and hopefully roll out a microcosm service to make it easy for clients (and demos), but there are a few more things in the pipeline to get to first. + + +### todo + +provide a pubkey-signed JWT of the identity (just the DID as `sub` probably). (**you probably SHOULD NOT USE THIS in any serious environment**) -- 2.51.2